Quick Emulator (Qemu) built with the VirtFS, host directory sharing via Plan 9 File System(9pfs) support, is vulnerable to an improper access control issue. It could occur while accessing virtfs metadata files in mapped-file security mode. A guest user could use this flaw to escalate their privileges inside guest.
Fixed in >=app-emulation/qemu-2.9.0-r2. Vulnerable version left in tree app-emulation/qemu-2.8.1-r2 commit 33cfc7b69e6a25e0b66687e28f7b29ae1a43e2d4 Author: Matthias Maier <tamiko@gentoo.org> Date: Wed May 17 23:08:31 2017 -0500 app-emulation/qemu: patch for CVE-2017-7493, bug #618808 Package-Manager: Portage-2.3.5, Repoman-2.3.2
Added to an existing GLSA Request.
This issue was resolved and addressed in GLSA 201706-03 at https://security.gentoo.org/glsa/201706-03 by GLSA coordinator Yury German (BlueKnight).