Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-2243

Опубликовано: 19 фев. 2026
Источник: debian
EPSS Низкий

Описание

A flaw was found in QEMU. A specially crafted VMDK image could trigger an out-of-bounds read vulnerability, potentially leading to a 12-byte leak of sensitive information or a denial of service condition (DoS).

Пакеты

ПакетСтатусВерсия исправленияРелизТип
qemufixed1:10.2.2+ds-1package
qemuno-dsatrixiepackage
qemuno-dsabookwormpackage
qemupostponedbullseyepackage

Примечания

  • https://lore.kernel.org/qemu-devel/CAJ9qJssSwxkmEVethg57-Ph6maEfButSaV-r07ma9_x1sp6wYg@mail.gmail.com/

  • Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/86b5130fefbe476f3c0a85b9e136f9e3fd518689 (v10.2.2)

EPSS

Процентиль: 2%
0.00114
Низкий

Связанные уязвимости

CVSS3: 5.1
ubuntu
4 месяца назад

A flaw was found in QEMU. A specially crafted VMDK image could trigger an out-of-bounds read vulnerability, potentially leading to a 12-byte leak of sensitive information or a denial of service condition (DoS).

CVSS3: 5.1
redhat
4 месяца назад

A flaw was found in QEMU. A specially crafted VMDK image could trigger an out-of-bounds read vulnerability, potentially leading to a 12-byte leak of sensitive information or a denial of service condition (DoS).

CVSS3: 5.1
nvd
4 месяца назад

A flaw was found in QEMU. A specially crafted VMDK image could trigger an out-of-bounds read vulnerability, potentially leading to a 12-byte leak of sensitive information or a denial of service condition (DoS).

msrc
4 месяца назад

Qemu-kvm: heap buffer out-of-bounds read in vmdk compressed grain parsing

CVSS3: 5.1
github
4 месяца назад

A flaw was found in QEMU. A specially crafted VMDK image could trigger an out-of-bounds read vulnerability, potentially leading to a 12-byte leak of sensitive information or a denial of service condition (DoS).

EPSS

Процентиль: 2%
0.00114
Низкий