{"id":"AZL-93006","summary":"CVE-2026-12080 affecting package qemu 9.1.0-11","details":"A flaw was found in the QEMU Guest Agent (qga). A local unprivileged user can exploit a vulnerability in the guest-ssh-add-authorized-keys command handler by manipulating symbolic links. This can occur either through a deterministic directory-symlink bypass or a Time-of-Check to Time-of-Use (TOCTOU) file-symlink race. Successful exploitation allows the attacker to gain ownership of arbitrary root-owned files or directories, leading to root access. This vulnerability requires an external management layer (e.g., libvirt) to trigger the affected code path.","modified":"2026-08-29T05:27:27Z","published":"2026-07-20T13:16:55Z","upstream":["CVE-2026-12080"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-12080"}],"affected":[{"package":{"name":"qemu","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/qemu"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"9.1.0-11"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-93006.json"}}],"schema_version":"1.9.0"}