← Back

Qemu

qemu

Vendor: Qemu • 419 CVEs

CVEs (419)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Debian
QemuRedhat
3Debian Linux
OpenstackQemu
May 13, 2026
May 23, 2017
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Memory leak in the audio/audio.c in QEMU (aka Quick Emulator) allows remote attackers to cause a denial of service (memory consumption) by repeatedly starting and stopping audio capture.
2Debian
Qemu
2Debian Linux
Qemu
May 13, 2026
May 17, 2017
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Quick Emulator (Qemu) built with the VirtFS, host directory sharing via Plan 9 File System(9pfs) support, is vulnerable to an improper access control issue. It could occur while accessing virtfs metadata files in mapped-...Show more
Quick Emulator (Qemu) built with the VirtFS, host directory sharing via Plan 9 File System(9pfs) support, is vulnerable to an improper access control issue. It could occur while accessing virtfs metadata files in mapped-file security mode. A guest user could use this flaw to escalate their privileges inside guest.Show less
2Debian
Qemu
2Debian Linux
Qemu
May 13, 2026
May 2, 2017
N/A· v4
6.5 MEDIUM· v3
4.9 MEDIUM· v2
hw/scsi/vmw_pvscsi.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (infinite loop and CPU consumption) via the message ring page count.
2Debian
Qemu
2Debian Linux
Qemu
May 13, 2026
May 2, 2017
N/A· v4
6.5 MEDIUM· v3
4.9 MEDIUM· v2
Memory leak in the v9fs_list_xattr function in hw/9pfs/9p-xattr.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (memory consumption) via vectors involving the orig_value...Show more
Memory leak in the v9fs_list_xattr function in hw/9pfs/9p-xattr.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (memory consumption) via vectors involving the orig_value variable.Show less
1Qemu
1Qemu
May 13, 2026
Apr 26, 2017
N/A· v4
7.0 HIGH· v3
6.9 MEDIUM· v2
The disas_insn function in target/i386/translate.c in QEMU before 2.9.0, when TCG mode without hardware acceleration is used, does not limit the instruction size, which allows local users to gain privileges by creating a...Show more
The disas_insn function in target/i386/translate.c in QEMU before 2.9.0, when TCG mode without hardware acceleration is used, does not limit the instruction size, which allows local users to gain privileges by creating a modified basic block that injects code into a setuid program, as demonstrated by procmail. NOTE: the vendor has stated "this bug does not violate any security guarantees QEMU makes.Show less
2Debian
Qemu
2Debian Linux
Qemu
May 13, 2026
Apr 20, 2017
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
hw/display/cirrus_vga_rop.h in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (out-of-bounds read and QEMU process crash) via vectors related to copying VGA data via the cir...Show more
hw/display/cirrus_vga_rop.h in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (out-of-bounds read and QEMU process crash) via vectors related to copying VGA data via the cirrus_bitblt_rop_fwd_transp_ and cirrus_bitblt_rop_fwd_ functions.Show less
2Debian
Qemu
2Debian Linux
Qemu
May 13, 2026
Apr 13, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Human Monitor Interface support in QEMU allows remote attackers to cause a denial of service (out-of-bounds write and application crash).
6Canonical
DebianFedoraproject+3 more
10Debian Linux
FedoraLeap+7 more
May 13, 2026
Apr 13, 2017
N/A· v4
7.7 HIGH· v3
6.8 MEDIUM· v2
Memory leak in net/vmxnet3.c in QEMU allows remote attackers to cause a denial of service (memory consumption).
2Debian
Qemu
2Debian Linux
Qemu
May 13, 2026
Apr 13, 2017
N/A· v4
6.5 MEDIUM· v3
2.1 LOW· v2
The eepro100 emulator in QEMU qemu-kvm blank allows local guest users to cause a denial of service (application crash and infinite loop) via vectors involving the command block list.
2Debian
Qemu
2Debian Linux
Qemu
May 13, 2026
Apr 11, 2017
N/A· v4
7.9 HIGH· v3
3.3 LOW· v2
Heap-based buffer overflow in QEMU, when built with the Q35-chipset-based PC system emulator.
2Debian
Qemu
2Debian Linux
Qemu
May 13, 2026
Apr 11, 2017
N/A· v4
6.5 MEDIUM· v3
1.9 LOW· v2
Stack-based buffer overflow in the megasas_ctrl_get_info function in QEMU, when built with SCSI MegaRAID SAS HBA emulation support, allows local guest users to cause a denial of service (QEMU instance crash) via a crafte...Show more
Stack-based buffer overflow in the megasas_ctrl_get_info function in QEMU, when built with SCSI MegaRAID SAS HBA emulation support, allows local guest users to cause a denial of service (QEMU instance crash) via a crafted SCSI controller CTRL_GET_INFO command.Show less
2Debian
Qemu
2Debian Linux
Qemu
May 13, 2026
Apr 11, 2017
N/A· v4
6.5 MEDIUM· v3
4.7 MEDIUM· v2
Memory leak in QEMU, when built with a VMWARE VMXNET3 paravirtual NIC emulator support, allows local guest users to cause a denial of service (host memory consumption) by trying to activate the vmxnet3 device repeatedly.
2Debian
Qemu
2Debian Linux
Qemu
May 13, 2026
Apr 11, 2017
N/A· v4
6.5 MEDIUM· v3
3.5 LOW· v2
Qemu, when built with VNC display driver support, allows remote attackers to cause a denial of service (arithmetic exception and application crash) via crafted SetPixelFormat messages from a client.
2Debian
Qemu
2Debian Linux
Qemu
May 13, 2026
Apr 10, 2017
N/A· v4
6.0 MEDIUM· v3
2.1 LOW· v2
The (1) v9fs_create and (2) v9fs_lcreate functions in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allow local guest OS privileged users to cause a denial of service (file descriptor or memory consumption) via vectors relat...Show more
The (1) v9fs_create and (2) v9fs_lcreate functions in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allow local guest OS privileged users to cause a denial of service (file descriptor or memory consumption) via vectors related to an already in-use fid.Show less
3Debian
QemuRedhat
4Debian Linux
OpenstackQemu+1 more
May 13, 2026
Mar 27, 2017
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The xhci_kick_epctx function in hw/usb/hcd-xhci.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (infinite loop and QEMU process crash) via vectors related to control tra...Show more
The xhci_kick_epctx function in hw/usb/hcd-xhci.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (infinite loop and QEMU process crash) via vectors related to control transfer descriptor sequence.Show less
1Qemu
1Qemu
May 13, 2026
Mar 27, 2017
N/A· v4
8.8 HIGH· v3
7.2 HIGH· v2
Integer overflow in hw/virtio/virtio-crypto.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (QEMU process crash) or possibly execute arbitrary code on the host via a cra...Show more
Integer overflow in hw/virtio/virtio-crypto.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (QEMU process crash) or possibly execute arbitrary code on the host via a crafted virtio-crypto request, which triggers a heap-based buffer overflow.Show less
1Qemu
1Qemu
May 13, 2026
Mar 27, 2017
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The cirrus_do_copy function in hw/display/cirrus_vga.c in QEMU (aka Quick Emulator), when cirrus graphics mode is VGA, allows local guest OS privileged users to cause a denial of service (divide-by-zero error and QEMU pr...Show more
The cirrus_do_copy function in hw/display/cirrus_vga.c in QEMU (aka Quick Emulator), when cirrus graphics mode is VGA, allows local guest OS privileged users to cause a denial of service (divide-by-zero error and QEMU process crash) via vectors involving blit pitch values.Show less
1Qemu
1Qemu
May 13, 2026
Mar 24, 2017
N/A· v4
10.0 CRITICAL· v3
10.0 HIGH· v2
Local privilege escalation vulnerability in the Gentoo QEMU package before 2.5.0-r1.
1Qemu
1Qemu
May 13, 2026
Mar 20, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Buffer overflow in NetRxPkt::ehdr_buf in hw/net/net_rx_pkt.c in QEMU (aka Quick Emulator), when the VLANSTRIP feature is enabled on the vmxnet3 device, allows remote attackers to cause a denial of service (out-of-bounds...Show more
Buffer overflow in NetRxPkt::ehdr_buf in hw/net/net_rx_pkt.c in QEMU (aka Quick Emulator), when the VLANSTRIP feature is enabled on the vmxnet3 device, allows remote attackers to cause a denial of service (out-of-bounds access and QEMU process crash) via vectors related to VLAN stripping.Show less
2Debian
Qemu
2Debian Linux
Qemu
May 13, 2026
Mar 20, 2017
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The sdhci_sdma_transfer_multi_blocks function in hw/sd/sdhci.c in QEMU (aka Quick Emulator) allows local OS guest privileged users to cause a denial of service (infinite loop and QEMU process crash) via vectors involving...Show more
The sdhci_sdma_transfer_multi_blocks function in hw/sd/sdhci.c in QEMU (aka Quick Emulator) allows local OS guest privileged users to cause a denial of service (infinite loop and QEMU process crash) via vectors involving the transfer mode register during multi block transfer.Show less