CVE-2026-0665
- EPSS 0.01%
- Veröffentlicht 18.02.2026 20:50:03
- Zuletzt bearbeitet 19.02.2026 15:53:02
An off-by-one error was found in QEMU's KVM Xen guest support. A malicious guest could use this flaw to trigger out-of-bounds heap accesses in the QEMU process via the emulated Xen physdev hypercall interface, leading to a denial of service or potent...
CVE-2025-8860
- EPSS 0.01%
- Veröffentlicht 18.02.2026 20:49:06
- Zuletzt bearbeitet 19.02.2026 15:53:02
A flaw was found in QEMU in the uefi-vars virtual device. When the guest writes to register UEFI_VARS_REG_BUFFER_SIZE, the .write callback `uefi_vars_write` is invoked. The function allocates a heap buffer without zeroing the memory, leaving the buff...
CVE-2025-14876
- EPSS 0.01%
- Veröffentlicht 18.02.2026 20:47:54
- Zuletzt bearbeitet 19.02.2026 15:53:02
A flaw was found in the virtio-crypto device of QEMU. A malicious guest operating system can exploit a missing length limit in the AKCIPHER path, leading to uncontrolled memory allocation. This can result in a denial of service (DoS) on the host syst...
CVE-2025-54566
- EPSS 0.01%
- Veröffentlicht 25.07.2025 03:15:33
- Zuletzt bearbeitet 16.12.2025 14:52:30
hw/pci/pcie_sriov.c in QEMU through 10.0.3 has a migration state inconsistency, a related issue to CVE-2024-26327.
CVE-2025-54567
- EPSS 0.01%
- Veröffentlicht 25.07.2025 03:15:33
- Zuletzt bearbeitet 16.12.2025 14:40:13
hw/pci/pcie_sriov.c in QEMU through 10.0.3 mishandles the VF Enable bit write mask, a related issue to CVE-2024-26327.
CVE-2024-7730
- EPSS 0.03%
- Veröffentlicht 14.11.2024 12:15:18
- Zuletzt bearbeitet 05.08.2025 18:26:29
A heap buffer overflow was found in the virtio-snd device in QEMU. When reading input audio in the virtio-snd input callback, virtio_snd_pcm_in_cb, the function did not check whether the iov can fit the data buffer. This issue can trigger an out-of-b...
- EPSS 0.02%
- Veröffentlicht 14.11.2024 12:15:17
- Zuletzt bearbeitet 03.11.2025 20:16:26
A heap-based buffer overflow was found in the SDHCI device emulation of QEMU. The bug is triggered when both `s->data_count` and the size of `s->fifo_buffer` are set to 0x200, leading to an out-of-bound access. A malicious guest could use this flaw ...
CVE-2024-6519
- EPSS 0.02%
- Veröffentlicht 21.10.2024 15:15:03
- Zuletzt bearbeitet 08.08.2025 16:13:16
A use-after-free vulnerability was found in the QEMU LSI53C895A SCSI Host Bus Adapter emulation. This issue can lead to a crash or VM escape.
CVE-2024-8612
- EPSS 0.05%
- Veröffentlicht 20.09.2024 18:15:04
- Zuletzt bearbeitet 02.10.2025 17:16:02
A flaw was found in QEMU, in the virtio-scsi, virtio-blk, and virtio-crypto devices. The size for virtqueue_push as set in virtio_scsi_complete_req / virtio_blk_req_complete / virito_crypto_req_complete could be larger than the true size of the data ...
CVE-2024-8354
- EPSS 0.05%
- Veröffentlicht 19.09.2024 11:15:10
- Zuletzt bearbeitet 21.11.2024 09:53:05
A flaw was found in QEMU. An assertion failure was present in the usb_ep_get() function in hw/net/core.c when trying to get the USB endpoint from a USB device. This flaw may allow a malicious unprivileged guest user to crash the QEMU process on the h...