Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4pq4-6gr5-cr69

Опубликовано: 18 фев. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

An off-by-one error was found in QEMU's KVM Xen guest support. A malicious guest could use this flaw to trigger out-of-bounds heap accesses in the QEMU process via the emulated Xen physdev hypercall interface, leading to a denial of service or potential memory corruption.

An off-by-one error was found in QEMU's KVM Xen guest support. A malicious guest could use this flaw to trigger out-of-bounds heap accesses in the QEMU process via the emulated Xen physdev hypercall interface, leading to a denial of service or potential memory corruption.

EPSS

Процентиль: 5%
0.00154
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-787

Связанные уязвимости

CVSS3: 6.5
ubuntu
7 месяцев назад

An off-by-one error was found in QEMU's KVM Xen guest support. A malicious guest could use this flaw to trigger out-of-bounds heap accesses in the QEMU process via the emulated Xen physdev hypercall interface, leading to a denial of service or potential memory corruption.

CVSS3: 6.5
redhat
9 месяцев назад

An off-by-one error was found in QEMU's KVM Xen guest support. A malicious guest could use this flaw to trigger out-of-bounds heap accesses in the QEMU process via the emulated Xen physdev hypercall interface, leading to a denial of service or potential memory corruption.

CVSS3: 6.5
nvd
7 месяцев назад

An off-by-one error was found in QEMU's KVM Xen guest support. A malicious guest could use this flaw to trigger out-of-bounds heap accesses in the QEMU process via the emulated Xen physdev hypercall interface, leading to a denial of service or potential memory corruption.

msrc
16 дней назад

Qemu-kvm: heap off-by-one in kvm xen physdevop_map_pirq

CVSS3: 6.5
debian
7 месяцев назад

An off-by-one error was found in QEMU's KVM Xen guest support. A malic ...

EPSS

Процентиль: 5%
0.00154
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-787