Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-3196

Опубликовано: 19 июн. 2026
Источник: debian

Описание

An integer overflow vulnerability was found in the virtio-snd device via PCM_INFO requests from the guest. A malicious guest can provide out-of-bounds stream counts, potentially leading to unbounded memory allocation on the host and a denial of service condition.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
qemufixed1:10.2.2+ds-1package
qemufixed1:10.0.10+ds-0+deb13u1trixiepackage
qemunot-affectedbookwormpackage
qemunot-affectedbullseyepackage

Примечания

  • https://lore.kernel.org/qemu-devel/20260220-virtio-snd-series-v1-0-207c4f7200a2@linaro.org/

  • Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/61679d7dcfa2dffc8fb115aa19b09e0e7cf5ea5c (v11.0.0-rc0)

  • Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/d84fbf241d0322f19adfbe466c60bed5f50de262 (v10.2.2)

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 2 месяцев назад

An integer overflow vulnerability was found in the virtio-snd device via PCM_INFO requests from the guest. A malicious guest can provide out-of-bounds stream counts, potentially leading to unbounded memory allocation on the host and a denial of service condition.

CVSS3: 5.5
redhat
6 месяцев назад

An integer overflow vulnerability was found in the virtio-snd device via PCM_INFO requests from the guest. A malicious guest can provide out-of-bounds stream counts, potentially leading to unbounded memory allocation on the host and a denial of service condition.

CVSS3: 5.5
nvd
около 2 месяцев назад

An integer overflow vulnerability was found in the virtio-snd device via PCM_INFO requests from the guest. A malicious guest can provide out-of-bounds stream counts, potentially leading to unbounded memory allocation on the host and a denial of service condition.

CVSS3: 5.5
msrc
около 1 месяца назад

Qemu-kvm: virtio-snd: integer overflow leading to unbounded memory allocation

CVSS3: 5.5
github
около 2 месяцев назад

An integer overflow vulnerability was found in the virtio-snd device via PCM_INFO requests from the guest. A malicious guest can provide out-of-bounds stream counts, potentially leading to unbounded memory allocation on the host and a denial of service condition.