CVE-2026-48914
Published: June 13, 2026Last modified: August 14, 2026
Description
A flaw was found in QEMU's virtio-blk device. The issue arises because the device does not properly validate the size of input descriptors before writing data. A malicious guest with high privileges could exploit this vulnerability by submitting a malformed virtio-blk SCSI request, leading to an out-of-bounds write in the host heap memory and a potential denial of service (DoS) for the QEMU process.
Severity score breakdown
| Parameter | Value |
|---|---|
| Base score | 6.7 |
| Attack Vector | LOCAL |
| Attack complexity | LOW |
| Privileges required | HIGH |
| User interaction | NONE |
| Scope | CHANGED |
| Confidentiality | NONE |
| Integrity impact | LOW |
| Availability impact | HIGH |
| Vector | CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:H |
Notes
Introduced with: https://gitlab.com/qemu-project/qemu/-/commit/f34e73cd69bdbdb9b1d56b288c5e14d6fff58165 (v?)
Status
| Product | Release | Package | Status |
|---|---|---|---|
| Alpaquita Linux | 23 LTS | qemu | Unknown (7.1.0-r4) |
| 25 LTS | qemu | Fixed (10.0.12-r0) | |
| Stream | qemu | Fixed (11.0.2-r0) |
References
- https://access.redhat.com/errata/RHSA-2026:39311
- https://access.redhat.com/security/cve/CVE-2026-48914
- https://bugzilla.redhat.com/show_bug.cgi?id=2488283
- https://gitlab.com/qemu-project/qemu/-/commit/aeea0c2804c42f24915467a1e4c70e649e39b8e0
- https://lore.kernel.org/qemu-devel/[email protected]/
- https://gitlab.com/qemu-project/qemu/-/commit/f5e2c6906cad9a84140e232f2e3eb7a46bf07f62
- https://gitlab.com/qemu-project/qemu/-/commit/d2e7fd9fe2a2ca7069007df1f1852d2ee7cc3cf0