CVE-2025-14876
Published: December 19, 2025Last modified: August 14, 2026
Description
A flaw was found in the virtio-crypto device of QEMU. A malicious guest operating system can exploit a missing length limit in the AKCIPHER path, leading to uncontrolled memory allocation. This can result in a denial of service (DoS) on the host system by causing the QEMU process to terminate unexpectedly.
Severity score breakdown
| Parameter | Value |
|---|---|
| Base score | 5.5 |
| Attack Vector | LOCAL |
| Attack complexity | LOW |
| Privileges required | LOW |
| User interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality | NONE |
| Integrity impact | NONE |
| Availability impact | HIGH |
| Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Status
| Product | Release | Package | Status |
|---|---|---|---|
| Alpaquita Linux | 23 LTS | qemu | Vulnerable (7.1.0-r4) |
| 25 LTS | qemu | Fixed (10.0.9-r0) | |
| Stream | qemu | Fixed (11.0.0-r0) |
References
- https://access.redhat.com/security/cve/CVE-2025-14876
- https://bugzilla.redhat.com/show_bug.cgi?id=2423549
- https://lore.kernel.org/qemu-devel/[email protected]/T/#m23301f54ff08e39a19faa2132912d8604e95db4e
- https://bugzilla.redhat.com/show_bug.cgi?id=2423549
- https://gitlab.com/qemu-project/qemu/-/commit/91c6438caffc880e999a7312825479685d659b44
- https://gitlab.com/qemu-project/qemu/-/commit/e649201bb96ae7e91a69d57392c8907ec085111e