Multiple QEMU exploitation paths were detailed for qemu-system-x86_64, showing how guest users could escalate to root inside Linux VMs by abusing emulator flaws and exposed virtual hardware. One write-up described a recent bug in QEMU's access_ptr handling that lets cross-page memory accesses spill into the next physical page after an unsigned underflow, enabling corruption of adjacent memory with x87 instructions such as FLDT and FSTPT/FSTP. Another described a long-standing TCG flaw in x86 iret and far call emulation affecting versions before 9.1, where ring 3 code can induce stack accesses under ring 0 assumptions, creating kernel write and address-leak primitives that can bypass protections including KASLR and sometimes kPTI.

Get the actors, campaigns, and ATT&CK mapping behind it.
6 events from the most recent confirmed update back to the earliest known activity.
kqx published a write-up describing a newer vulnerability in qemu-system-x86_64 from QEMU 9.1 onward, caused by an unsigned underflow in access_ptr during guest memory accesses. The bug can let FLDT, FSTPT, and related instructions cross into the next physical page and be exploited for guest local privilege escalation to root.
The coalmine and gitvfs challenge environments initially used an older qemu-system-x86_64, but organizers rebuilt the containers with the latest QEMU to address an older bug. The updated environments reportedly remained exploitable because the newer QEMU version still contained a different vulnerability.
kqx published a write-up describing exploitation of a long-standing QEMU x86 TCG bug affecting iret and far call, including kPTI-off and kPTI-on paths to kernel compromise. The post states Ubuntu 24.04's default QEMU 8.2 remained vulnerable while versions before 9.1 were affected.
kqx published a proof-of-concept technique showing how an x86 primitive that raises IOPL to 3 can be combined with QEMU's fw_cfg DMA interface to perform arbitrary physical memory writes and patch __sys_setuid for root. The post also showed initrd dumping and an alternative byte-source trick using the fw_cfg signature string "QEMU."
Exodus Intelligence published a blog post titled "Mind the Patch Gap: Exploiting an io_uring Vulnerability in Ubuntu." The provided reference includes no further event details beyond the publication itself.
According to the write-up, a vulnerability in QEMU's x86 TCG handling of iret and far call affected all versions prior to 9.1 and was patched in QEMU v9.1.0-rc0. The flaw could let ring 3 code trigger stack accesses as if executing at ring 0, enabling kernel-memory exploitation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
4 references tracked. Mallory keeps watching after this page renders.
kqx.io
Open sourcekqx.io
Open sourcekqx.io
Open sourceblog.exodusintel.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.