Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-crqh-2v7r-3m9w

Опубликовано: 19 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 5.5

Описание

An integer overflow vulnerability was found in the virtio-snd device via PCM_INFO requests from the guest. A malicious guest can provide out-of-bounds stream counts, potentially leading to unbounded memory allocation on the host and a denial of service condition.

An integer overflow vulnerability was found in the virtio-snd device via PCM_INFO requests from the guest. A malicious guest can provide out-of-bounds stream counts, potentially leading to unbounded memory allocation on the host and a denial of service condition.

EPSS

Процентиль: 4%
0.00143
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-190

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 2 месяцев назад

An integer overflow vulnerability was found in the virtio-snd device via PCM_INFO requests from the guest. A malicious guest can provide out-of-bounds stream counts, potentially leading to unbounded memory allocation on the host and a denial of service condition.

CVSS3: 5.5
redhat
6 месяцев назад

An integer overflow vulnerability was found in the virtio-snd device via PCM_INFO requests from the guest. A malicious guest can provide out-of-bounds stream counts, potentially leading to unbounded memory allocation on the host and a denial of service condition.

CVSS3: 5.5
nvd
около 2 месяцев назад

An integer overflow vulnerability was found in the virtio-snd device via PCM_INFO requests from the guest. A malicious guest can provide out-of-bounds stream counts, potentially leading to unbounded memory allocation on the host and a denial of service condition.

CVSS3: 5.5
msrc
около 1 месяца назад

Qemu-kvm: virtio-snd: integer overflow leading to unbounded memory allocation

CVSS3: 5.5
debian
около 2 месяцев назад

An integer overflow vulnerability was found in the virtio-snd device v ...

EPSS

Процентиль: 4%
0.00143
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-190