← Back

Qemu

qemu

Vendor: Qemu • 419 CVEs

CVEs (419)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Opensuse
QemuRedhat
4Leap
OpenstackQemu+1 more
May 6, 2026
Dec 10, 2016
N/A· v4
6.0 MEDIUM· v3
2.1 LOW· v2
The virtqueue_map_desc function in hw/virtio/virtio.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (NULL pointer dereference and QEMU process crash) via a large I/O descr...Show more
The virtqueue_map_desc function in hw/virtio/virtio.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (NULL pointer dereference and QEMU process crash) via a large I/O descriptor buffer length value.Show less
2Debian
Qemu
2Debian Linux
Qemu
May 6, 2026
Dec 10, 2016
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
The pvscsi_ring_pop_req_descr function in hw/scsi/vmw_pvscsi.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) by leveraging failure t...Show more
The pvscsi_ring_pop_req_descr function in hw/scsi/vmw_pvscsi.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) by leveraging failure to limit process IO loop to the ring size.Show less
3Debian
OpensuseQemu
3Debian Linux
LeapQemu
May 6, 2026
Dec 10, 2016
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
The vmsvga_fifo_run function in hw/display/vmware_vga.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (out-of-bounds write and QEMU process crash) via vectors related to c...Show more
The vmsvga_fifo_run function in hw/display/vmware_vga.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (out-of-bounds write and QEMU process crash) via vectors related to cursor.mask[] and cursor.image[] array sizes when processing a DEFINE_CURSOR svga command.Show less
1Qemu
1Qemu
May 6, 2026
Dec 10, 2016
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
The (1) mptsas_config_manufacturing_1 and (2) mptsas_config_ioc_0 functions in hw/scsi/mptconfig.c in QEMU (aka Quick Emulator) allow local guest OS administrators to cause a denial of service (QEMU process crash) via ve...Show more
The (1) mptsas_config_manufacturing_1 and (2) mptsas_config_ioc_0 functions in hw/scsi/mptconfig.c in QEMU (aka Quick Emulator) allow local guest OS administrators to cause a denial of service (QEMU process crash) via vectors involving MPTSAS_CONFIG_PACK.Show less
2Debian
Qemu
2Debian Linux
Qemu
May 6, 2026
Dec 10, 2016
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
The pvscsi_convert_sglist function in hw/scsi/vmw_pvscsi.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) by leveraging an incorrect...Show more
The pvscsi_convert_sglist function in hw/scsi/vmw_pvscsi.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) by leveraging an incorrect cast.Show less
2Debian
Qemu
2Debian Linux
Qemu
May 6, 2026
Dec 10, 2016
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
hw/scsi/vmw_pvscsi.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (out-of-bounds access or infinite loop, and QEMU process crash) via a crafted page count for descriptor...Show more
hw/scsi/vmw_pvscsi.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (out-of-bounds access or infinite loop, and QEMU process crash) via a crafted page count for descriptor rings.Show less
2Debian
Qemu
2Debian Linux
Qemu
May 6, 2026
Dec 10, 2016
N/A· v4
6.0 MEDIUM· v3
2.1 LOW· v2
Directory traversal vulnerability in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to access host files outside the export path via a .. (dot dot) in an unspecified string.
3Debian
QemuRedhat
4Debian Linux
OpenstackQemu+1 more
May 6, 2026
Dec 10, 2016
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
Integer overflow in the net_tx_pkt_init function in hw/net/net_tx_pkt.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (QEMU process crash) via the maximum fragmentation co...Show more
Integer overflow in the net_tx_pkt_init function in hw/net/net_tx_pkt.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (QEMU process crash) via the maximum fragmentation count, which triggers an unchecked multiplication and NULL pointer dereference.Show less
2Debian
Qemu
2Debian Linux
Qemu
May 6, 2026
Dec 10, 2016
N/A· v4
6.0 MEDIUM· v3
2.1 LOW· v2
The vmxnet3_complete_packet function in hw/net/vmxnet3.c in QEMU (aka Quick Emulator) allows local guest OS administrators to obtain sensitive host memory information by leveraging failure to initialize the txcq_descr ob...Show more
The vmxnet3_complete_packet function in hw/net/vmxnet3.c in QEMU (aka Quick Emulator) allows local guest OS administrators to obtain sensitive host memory information by leveraging failure to initialize the txcq_descr object.Show less
3Debian
QemuRedhat
3Debian Linux
QemuVirtualization
May 6, 2026
Dec 10, 2016
N/A· v4
6.0 MEDIUM· v3
2.1 LOW· v2
The vmxnet_tx_pkt_parse_headers function in hw/net/vmxnet_tx_pkt.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (buffer over-read) by leveraging failure to check IP heade...Show more
The vmxnet_tx_pkt_parse_headers function in hw/net/vmxnet_tx_pkt.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (buffer over-read) by leveraging failure to check IP header length.Show less
2Debian
Qemu
2Debian Linux
Qemu
May 6, 2026
Dec 10, 2016
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
The net_tx_pkt_do_sw_fragmentation function in hw/net/net_tx_pkt.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) via a zero length f...Show more
The net_tx_pkt_do_sw_fragmentation function in hw/net/net_tx_pkt.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) via a zero length for the current fragment length.Show less
2Debian
Qemu
2Debian Linux
Qemu
May 6, 2026
Dec 10, 2016
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
Use-after-free vulnerability in the vmxnet3_io_bar0_write function in hw/net/vmxnet3.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (QEMU instance crash) by leveraging fa...Show more
Use-after-free vulnerability in the vmxnet3_io_bar0_write function in hw/net/vmxnet3.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (QEMU instance crash) by leveraging failure to check if the device is active.Show less
1Qemu
1Qemu
May 6, 2026
Dec 10, 2016
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
The virtqueue_map_desc function in hw/virtio/virtio.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) via a zero length for the descri...Show more
The virtqueue_map_desc function in hw/virtio/virtio.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) via a zero length for the descriptor buffer.Show less
1Qemu
1Qemu
May 6, 2026
Dec 10, 2016
N/A· v4
6.0 MEDIUM· v3
4.9 MEDIUM· v2
The mptsas_fetch_requests function in hw/scsi/mptsas.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop, and CPU consumption or QEMU process crash) via vectors...Show more
The mptsas_fetch_requests function in hw/scsi/mptsas.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop, and CPU consumption or QEMU process crash) via vectors involving s->state.Show less
3Debian
OpensuseQemu
3Debian Linux
LeapQemu
May 6, 2026
Dec 9, 2016
N/A· v4
6.0 MEDIUM· v3
2.1 LOW· v2
Memory leak in the v9fs_write function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption) by leveraging failure to free an IO vector.
3Debian
OpensuseQemu
3Debian Linux
LeapQemu
May 6, 2026
Dec 9, 2016
N/A· v4
6.0 MEDIUM· v3
2.1 LOW· v2
Memory leak in the v9fs_link function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption) via vectors involving a reference to the source fi...Show more
Memory leak in the v9fs_link function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption) via vectors involving a reference to the source fid object.Show less
3Debian
OpensuseQemu
3Debian Linux
LeapQemu
May 6, 2026
Dec 9, 2016
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
Multiple integer overflows in the (1) v9fs_xattr_read and (2) v9fs_xattr_write functions in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allow local guest OS administrators to cause a denial of service (QEMU process crash)...Show more
Multiple integer overflows in the (1) v9fs_xattr_read and (2) v9fs_xattr_write functions in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allow local guest OS administrators to cause a denial of service (QEMU process crash) via a crafted offset, which triggers an out-of-bounds access.Show less
2Debian
Qemu
2Debian Linux
Qemu
May 6, 2026
Dec 9, 2016
N/A· v4
6.0 MEDIUM· v3
2.1 LOW· v2
The v9fs_xattrcreate function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to obtain sensitive host heap memory information by reading xattribute values before writing to them.
2Debian
Qemu
2Debian Linux
Qemu
May 6, 2026
Dec 9, 2016
N/A· v4
6.0 MEDIUM· v3
2.1 LOW· v2
Memory leak in the v9fs_xattrcreate function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption and QEMU process crash) via a large number o...Show more
Memory leak in the v9fs_xattrcreate function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption and QEMU process crash) via a large number of Txattrcreate messages with the same fid number.Show less
3Debian
OpensuseQemu
3Debian Linux
LeapQemu
May 6, 2026
Dec 9, 2016
N/A· v4
6.0 MEDIUM· v3
2.1 LOW· v2
Memory leak in hw/net/eepro100.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption and QEMU process crash) by repeatedly unplugging an i8255x (PRO100) NIC...Show more
Memory leak in hw/net/eepro100.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption and QEMU process crash) by repeatedly unplugging an i8255x (PRO100) NIC device.Show less