← Back

Qemu

qemu

419 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Qemu
qemu

CVEs (419)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Debian
FedoraprojectQemu
3Debian Linux
FedoraQemu
Jun 17, 2026
Mar 23, 2021
N/A· v4
3.2 LOW· v3
2.1 LOW· v2
A use-after-free flaw was found in the MegaRAID emulator of QEMU. This issue occurs while processing SCSI I/O requests in the case of an error mptsas_free_request() that does not dequeue the request object 'req' from a p...Show more
A use-after-free flaw was found in the MegaRAID emulator of QEMU. This issue occurs while processing SCSI I/O requests in the case of an error mptsas_free_request() that does not dequeue the request object 'req' from a pending requests queue. This flaw allows a privileged guest user to crash the QEMU process on the host, resulting in a denial of service. Versions between 2.10.0 and 5.2.0 are potentially affected.Show less
4Debian
FedoraprojectQemu+1 more
4Debian Linux
Enterprise LinuxFedora+1 more
Jun 17, 2026
Mar 18, 2021
N/A· v4
6.0 MEDIUM· v3
2.1 LOW· v2
A potential stack overflow via infinite loop issue was found in various NIC emulators of QEMU in versions up to and including 5.2.0. The issue occurs in loopback mode of a NIC wherein reentrant DMA checks get bypassed. A...Show more
A potential stack overflow via infinite loop issue was found in various NIC emulators of QEMU in versions up to and including 5.2.0. The issue occurs in loopback mode of a NIC wherein reentrant DMA checks get bypassed. A guest user/process may use this flaw to consume CPU cycles or crash the QEMU process on the host resulting in DoS scenario.Show less
2Debian
Qemu
2Debian Linux
Qemu
Jun 17, 2026
Mar 9, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A stack overflow via an infinite recursion vulnerability was found in the eepro100 i8255x device emulator of QEMU. This issue occurs while processing controller commands due to a DMA reentry issue. This flaw allows a gue...Show more
A stack overflow via an infinite recursion vulnerability was found in the eepro100 i8255x device emulator of QEMU. This issue occurs while processing controller commands due to a DMA reentry issue. This flaw allows a guest user or process to consume CPU cycles or crash the QEMU process on the host, resulting in a denial of service. The highest threat from this vulnerability is to system availability.Show less
1Qemu
1Qemu
Jun 17, 2026
Mar 9, 2021
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
A flaw was found in the virtio-fs shared file system daemon (virtiofsd) of QEMU. The new 'xattrmap' option may cause the 'security.capability' xattr in the guest to not drop on file write, potentially leading to a modifi...Show more
A flaw was found in the virtio-fs shared file system daemon (virtiofsd) of QEMU. The new 'xattrmap' option may cause the 'security.capability' xattr in the guest to not drop on file write, potentially leading to a modified, privileged executable in the guest. In rare circumstances, this flaw could be used by a malicious user to elevate their privileges within the guest.Show less
3Debian
FedoraprojectQemu
3Debian Linux
FedoraQemu
Jun 17, 2026
Feb 25, 2021
N/A· v4
3.2 LOW· v3
2.1 LOW· v2
An integer overflow issue was found in the vmxnet3 NIC emulator of the QEMU for versions up to v5.2.0. It may occur if a guest was to supply invalid values for rx/tx queue size or other NIC parameters. A privileged guest...Show more
An integer overflow issue was found in the vmxnet3 NIC emulator of the QEMU for versions up to v5.2.0. It may occur if a guest was to supply invalid values for rx/tx queue size or other NIC parameters. A privileged guest user may use this flaw to crash the QEMU process on the host resulting in DoS scenario.Show less
2Debian
Qemu
2Debian Linux
Qemu
Jun 17, 2026
Jan 30, 2021
N/A· v4
6.3 MEDIUM· v3
4.6 MEDIUM· v2
A heap-based buffer overflow was found in QEMU through 5.0.0 in the SDHCI device emulation support. It could occur while doing a multi block SDMA transfer via the sdhci_sdma_transfer_multi_blocks() routine in hw/sd/sdhci...Show more
A heap-based buffer overflow was found in QEMU through 5.0.0 in the SDHCI device emulation support. It could occur while doing a multi block SDMA transfer via the sdhci_sdma_transfer_multi_blocks() routine in hw/sd/sdhci.c. A guest user or process could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition, or potentially execute arbitrary code with privileges of the QEMU process on the host.Show less
1Qemu
1Qemu
Jun 17, 2026
Jan 28, 2021
N/A· v4
8.2 HIGH· v3
4.6 MEDIUM· v2
A flaw was found in qemu. A host privilege escalation issue was found in the virtio-fs shared file system daemon where a privileged guest user is able to create a device special file in the shared directory and use it to...Show more
A flaw was found in qemu. A host privilege escalation issue was found in the virtio-fs shared file system daemon where a privileged guest user is able to create a device special file in the shared directory and use it to r/w access host devices.Show less
2Debian
Qemu
2Debian Linux
Qemu
Jun 17, 2026
Jan 26, 2021
N/A· v4
3.9 LOW· v3
3.3 LOW· v2
ide_atapi_cmd_reply_end in hw/ide/atapi.c in QEMU 5.1.0 allows out-of-bounds read access because a buffer index is not validated.
1Qemu
1Qemu
Jun 17, 2026
Dec 31, 2020
N/A· v4
3.8 LOW· v3
2.1 LOW· v2
iscsi_aio_ioctl_cb in block/iscsi.c in QEMU 4.1.0 has a heap-based buffer over-read that may disclose unrelated information from process memory to an attacker.
1Qemu
1Qemu
Jun 17, 2026
Dec 31, 2020
N/A· v4
6.5 MEDIUM· v3
2.1 LOW· v2
In QEMU 4.1.0, an out-of-bounds read flaw was found in the ATI VGA implementation. It occurs in the ati_cursor_define() routine while handling MMIO write operations through the ati_mm_write() callback. A malicious guest...Show more
In QEMU 4.1.0, an out-of-bounds read flaw was found in the ATI VGA implementation. It occurs in the ati_cursor_define() routine while handling MMIO write operations through the ati_mm_write() callback. A malicious guest could abuse this flaw to crash the QEMU process, resulting in a denial of service.Show less
2Debian
Qemu
2Debian Linux
Qemu
Jun 17, 2026
Dec 8, 2020
N/A· v4
6.0 MEDIUM· v3
2.1 LOW· v2
A flaw was found in the memory management API of QEMU during the initialization of a memory region cache. This issue could lead to an out-of-bounds write access to the MSI-X table while performing MMIO operations. A gues...Show more
A flaw was found in the memory management API of QEMU during the initialization of a memory region cache. This issue could lead to an out-of-bounds write access to the MSI-X table while performing MMIO operations. A guest user may abuse this flaw to crash the QEMU process on the host, resulting in a denial of service. This flaw affects QEMU versions prior to 5.2.0.Show less
2Debian
Qemu
2Debian Linux
Qemu
Jun 17, 2026
Dec 4, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
hw/net/e1000e_core.c in QEMU 5.0.0 has an infinite loop via an RX descriptor with a NULL buffer address.
2Debian
Qemu
2Debian Linux
Qemu
Jun 17, 2026
Dec 2, 2020
N/A· v4
3.2 LOW· v3
2.1 LOW· v2
A reachable assertion issue was found in the USB EHCI emulation code of QEMU. It could occur while processing USB requests due to missing handling of DMA memory map failure. A malicious privileged user within the guest m...Show more
A reachable assertion issue was found in the USB EHCI emulation code of QEMU. It could occur while processing USB requests due to missing handling of DMA memory map failure. A malicious privileged user within the guest may abuse this flaw to send bogus USB requests and crash the QEMU process on the host, resulting in a denial of service.Show less
2Debian
Qemu
2Debian Linux
Qemu
Jun 17, 2026
Nov 30, 2020
N/A· v4
5.0 MEDIUM· v3
4.4 MEDIUM· v2
hw/usb/hcd-ohci.c in QEMU 5.0.0 has a stack-based buffer over-read via values obtained from the host controller driver.
2Debian
Qemu
2Debian Linux
Qemu
Jun 17, 2026
Nov 6, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
eth_get_gso_type in net/eth.c in QEMU 4.2.1 allows guest OS users to trigger an assertion failure. A guest can crash the QEMU process via packet data that lacks a valid Layer 3 protocol.
1Qemu
1Qemu
Jun 17, 2026
Nov 6, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
ati_2d_blt in hw/display/ati_2d.c in QEMU 4.2.1 can encounter an outside-limits situation in a calculation. A guest can crash the QEMU process.
1Qemu
1Qemu
Jun 17, 2026
Oct 16, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
An issue was discovered in QEMU through 5.1.0. An out-of-bounds memory access was found in the ATI VGA device implementation. This flaw occurs in the ati_2d_blt() routine in hw/display/ati_2d.c while handling MMIO write...Show more
An issue was discovered in QEMU through 5.1.0. An out-of-bounds memory access was found in the ATI VGA device implementation. This flaw occurs in the ati_2d_blt() routine in hw/display/ati_2d.c while handling MMIO write operations through the ati_mm_write() callback. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service.Show less
2Qemu
Redhat
3Enterprise Linux
Openstack PlatformQemu
Jun 17, 2026
Oct 6, 2020
N/A· v4
3.2 LOW· v3
2.1 LOW· v2
hw/ide/pci.c in QEMU before 5.1.1 can trigger a NULL pointer dereference because it lacks a pointer check before an ide_cancel_dma_sync call.
1Qemu
1Qemu
Jun 17, 2026
Oct 6, 2020
N/A· v4
3.2 LOW· v3
2.1 LOW· v2
pci_change_irq_level in hw/pci/pci.c in QEMU before 5.1.1 has a NULL pointer dereference because pci_get_bus() might not return a valid pointer.
1Qemu
1Qemu
Jun 17, 2026
Oct 2, 2020
N/A· v4
3.2 LOW· v3
2.1 LOW· v2
fdctrl_write_data in hw/block/fdc.c in QEMU 5.0.0 has a NULL pointer dereference via a NULL block pointer for the current drive.