Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4pq4-6gr5-cr69

Опубликовано: 18 фев. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

An off-by-one error was found in QEMU's KVM Xen guest support. A malicious guest could use this flaw to trigger out-of-bounds heap accesses in the QEMU process via the emulated Xen physdev hypercall interface, leading to a denial of service or potential memory corruption.

An off-by-one error was found in QEMU's KVM Xen guest support. A malicious guest could use this flaw to trigger out-of-bounds heap accesses in the QEMU process via the emulated Xen physdev hypercall interface, leading to a denial of service or potential memory corruption.

EPSS

Процентиль: 1%
0.00008
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-787

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 1 месяца назад

An off-by-one error was found in QEMU's KVM Xen guest support. A malicious guest could use this flaw to trigger out-of-bounds heap accesses in the QEMU process via the emulated Xen physdev hypercall interface, leading to a denial of service or potential memory corruption.

CVSS3: 6.5
redhat
3 месяца назад

An off-by-one error was found in QEMU's KVM Xen guest support. A malicious guest could use this flaw to trigger out-of-bounds heap accesses in the QEMU process via the emulated Xen physdev hypercall interface, leading to a denial of service or potential memory corruption.

CVSS3: 6.5
nvd
около 1 месяца назад

An off-by-one error was found in QEMU's KVM Xen guest support. A malicious guest could use this flaw to trigger out-of-bounds heap accesses in the QEMU process via the emulated Xen physdev hypercall interface, leading to a denial of service or potential memory corruption.

CVSS3: 6.5
debian
около 1 месяца назад

An off-by-one error was found in QEMU's KVM Xen guest support. A malic ...

suse-cvrf
около 2 месяцев назад

Security update for qemu

EPSS

Процентиль: 1%
0.00008
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-787