The ssi_sd_transfer function in hw/sd/ssi-sd
The ssi_sd_transfer function in hw/sd/ssi-sd.c in QEMU before 1.7.2 allows remote attackers to execute arbitrary code via a crafted arglen value in a savevm image.
Exploitability
AV:N
AC:L
Au:N
Impact
C:P
I:P
A:P
7.5/AV:N/AC:L/Au:N/C:P/I:P/A:P