Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-39311

Опубликовано: 14 июл. 2026
Источник: oracle-oval
Платформа: Oracle Linux 9

Описание

ELSA-2026-39311: qemu-kvm security update (LOW)

[10.1.0-17.el9_8.4]

  • kvm-virtio-blk-add-missing-VIRTIO_BLK_T_SCSI_CMD-size-ch.patch [RHEL-184527]
  • Resolves: RHEL-184527 (CVE-2026-48914 qemu-kvm: Heap buffer overflow in virtio-blk SCSI request handling [rhel-9.8.z])

Обновленные пакеты

Oracle Linux 9

Oracle Linux aarch64

qemu-guest-agent

10.1.0-17.el9_8.4

qemu-img

10.1.0-17.el9_8.4

qemu-kvm

10.1.0-17.el9_8.4

qemu-kvm-audio-pa

10.1.0-17.el9_8.4

qemu-kvm-block-blkio

10.1.0-17.el9_8.4

qemu-kvm-block-curl

10.1.0-17.el9_8.4

qemu-kvm-block-rbd

10.1.0-17.el9_8.4

qemu-kvm-common

10.1.0-17.el9_8.4

qemu-kvm-core

10.1.0-17.el9_8.4

qemu-kvm-device-display-virtio-gpu

10.1.0-17.el9_8.4

qemu-kvm-device-display-virtio-gpu-pci

10.1.0-17.el9_8.4

qemu-kvm-device-usb-host

10.1.0-17.el9_8.4

qemu-kvm-device-usb-redirect

10.1.0-17.el9_8.4

qemu-kvm-docs

10.1.0-17.el9_8.4

qemu-kvm-tools

10.1.0-17.el9_8.4

qemu-pr-helper

10.1.0-17.el9_8.4

Oracle Linux x86_64

qemu-guest-agent

10.1.0-17.el9_8.4

qemu-img

10.1.0-17.el9_8.4

qemu-kvm

10.1.0-17.el9_8.4

qemu-kvm-audio-pa

10.1.0-17.el9_8.4

qemu-kvm-block-blkio

10.1.0-17.el9_8.4

qemu-kvm-block-curl

10.1.0-17.el9_8.4

qemu-kvm-block-rbd

10.1.0-17.el9_8.4

qemu-kvm-common

10.1.0-17.el9_8.4

qemu-kvm-core

10.1.0-17.el9_8.4

qemu-kvm-device-display-virtio-gpu

10.1.0-17.el9_8.4

qemu-kvm-device-display-virtio-gpu-pci

10.1.0-17.el9_8.4

qemu-kvm-device-display-virtio-vga

10.1.0-17.el9_8.4

qemu-kvm-device-usb-host

10.1.0-17.el9_8.4

qemu-kvm-device-usb-redirect

10.1.0-17.el9_8.4

qemu-kvm-docs

10.1.0-17.el9_8.4

qemu-kvm-tools

10.1.0-17.el9_8.4

qemu-kvm-ui-egl-headless

10.1.0-17.el9_8.4

qemu-kvm-ui-opengl

10.1.0-17.el9_8.4

qemu-pr-helper

10.1.0-17.el9_8.4

Связанные CVE

Связанные уязвимости

CVSS3: 6.7
ubuntu
около 2 месяцев назад

A flaw was found in QEMU's virtio-blk device. The issue arises because the device does not properly validate the size of input descriptors before writing data. A malicious guest with high privileges could exploit this vulnerability by submitting a malformed virtio-blk SCSI request, leading to an out-of-bounds write in the host heap memory and a potential denial of service (DoS) for the QEMU process.

CVSS3: 6.7
redhat
2 месяца назад

A flaw was found in QEMU's virtio-blk device. The issue arises because the device does not properly validate the size of input descriptors before writing data. A malicious guest with high privileges could exploit this vulnerability by submitting a malformed virtio-blk SCSI request, leading to an out-of-bounds write in the host heap memory and a potential denial of service (DoS) for the QEMU process.

CVSS3: 6.7
nvd
около 2 месяцев назад

A flaw was found in QEMU's virtio-blk device. The issue arises because the device does not properly validate the size of input descriptors before writing data. A malicious guest with high privileges could exploit this vulnerability by submitting a malformed virtio-blk SCSI request, leading to an out-of-bounds write in the host heap memory and a potential denial of service (DoS) for the QEMU process.

CVSS3: 6.7
msrc
около 1 месяца назад

Qemu-kvm: heap buffer overflow in virtio-blk scsi request handling

CVSS3: 6.7
debian
около 2 месяцев назад

A flaw was found in QEMU's virtio-blk device. The issue arises because ...