CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2023-1386

mediumCVSS 6.5covered by 1 sourcefirst seen 2026-08-06

CSIRTS triage

What
The 9pfs implementation fails to drop suid and sgid bits when files are written, potentially allowing privilege escalation.
Who is affected
Systems running QEMU with 9pfs filesystem support enabled.
Urgency
Medium severity; no active exploitation reported but privilege escalation is a critical attack vector.
Action
Upgrade QEMU to a patched version once available.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2023-1386

Get an email if CVE-2023-1386 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2023-1386

CVE.org record

Embed the live status

CVE-2023-1386 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2023-1386 status](https://www.csirts.com/badge/CVE-2023-1386)](https://www.csirts.com/cve/CVE-2023-1386)