QEMU (aka Quick Emulator) built with the Virtio GPU Device emulator support is vulnerable to an information leakage issue. It could occur while processing 'VIRTIO_GPU_CMD_GET_CAPSET_INFO' command. A guest user/process could use this flaw to leak contents of the host memory bytes.
| Software | From | Fixed in |
|---|---|---|
| qemu / qemu | - | 2.8.0 |
| qemu / qemu | 2.8.0-rc0 | 2.8.0-rc0.x |
| qemu / qemu | 2.8.0-rc1 | 2.8.0-rc1.x |
| qemu / qemu | 2.8.0-rc2 | 2.8.0-rc2.x |