The megasasctrlget_info function in hw/scsi/megasas.c in QEMU allows local guest OS administrators to obtain sensitive host memory information via vectors related to reading device control information.
{ "urgency": "not yet assigned" }