Integer overflow in the virtio_net_handle_mac function in hw/net/virtio-net.c in QEMU 2.0 and earlier allows local guest users to execute arbitrary code via a MAC addresses table update request, which triggers a heap-based buffer overflow.
No PoCs from references.
- https://github.com/cloudpassage-community/vulnerable_image_check
- https://github.com/cloudpassage/vulnerable_image_check