tcmu-runner version 0.91 up to 1.20 is vulnerable to information disclosure in handler_qcow.so resulting in non-privileged users being able to check for existence of any file with root privileges.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-1000199.json"