A series of posts about QEMU internals:
À voir, pour les optimisations
Quickly create and run optimised Windows, macOS and Linux desktop virtual machines. - GitHub - wimpysworld/quickemu: Quickly create and run optimised Windows, macOS and Linux desktop virtual machines.
The new vuln glories in the name XSA-138, aka CVE-2015-5154 and means “An HVM guest which has access to an emulated IDE CDROM device (e.g. with a device with "devtype=cdrom", or the "cdrom" convenience alias, in the VBD configuration) can exploit this vulnerability to take over the qemu process elevating its privilege to that of the qemu process.”
Dubbed VENOM (Virtualized Environment Neglected Operations Manipulation), the zero-day flaw takes advantage of the “virtual floppy disk controller” and potentially allows attackers to escape out of the virtual machine and execute malicious code on its host.
montage vdisk raw (avec offset) et qcow2 (avec nbd).
Alternative, avec guestmount
https://www.xmodulo.com/mount-qcow2-disk-image-linux.html