Описание
A flaw was found in QEMU. If the QIOChannelWebsock object is freed while it is waiting to complete a handshake, a GSource is leaked. This can lead to the callback firing later on and triggering a use-after-free in the use of the channel. This can be abused by a malicious client with network access to the VNC WebSocket port to cause a denial of service during the WebSocket handshake prior to the VNC client authentication.
Отчет
This CVE has been rated as Moderate because it only affects the WebSocket protocol for communication (the VNC raw TCP socket is not affected) and the use of QEMU's in-process WebSocket feature is fairly niche.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | qemu-kvm | Not affected | ||
| Red Hat Enterprise Linux 7 | qemu-kvm | Not affected | ||
| Red Hat Enterprise Linux 7 | qemu-kvm-ma | Affected | ||
| Red Hat Enterprise Linux 8 | virt:rhel/qemu-kvm | Affected | ||
| Red Hat Enterprise Linux 9 | qemu-kvm | Affected | ||
| Red Hat Enterprise Linux 10 | qemu-kvm | Fixed | RHSA-2026:1831 | 05.02.2026 |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | qemu-kvm | Fixed | RHSA-2026:3077 | 23.02.2026 |
| Red Hat Enterprise Linux 9.4 Extended Update Support | qemu-kvm | Fixed | RHSA-2025:23228 | 17.12.2025 |
| Red Hat Enterprise Linux 9.4 Extended Update Support | qemu-kvm | Fixed | RHSA-2026:3165 | 24.02.2026 |
| Red Hat OpenShift Container Platform 4.16 | rhcos-416.94.202601071926 | Fixed | RHSA-2026:0326 | 15.01.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
A flaw was found in QEMU. If the QIOChannelWebsock object is freed while it is waiting to complete a handshake, a GSource is leaked. This can lead to the callback firing later on and triggering a use-after-free in the use of the channel. This can be abused by a malicious client with network access to the VNC WebSocket port to cause a denial of service during the WebSocket handshake prior to the VNC client authentication.
A flaw was found in QEMU. If the QIOChannelWebsock object is freed while it is waiting to complete a handshake, a GSource is leaked. This can lead to the callback firing later on and triggering a use-after-free in the use of the channel. This can be abused by a malicious client with network access to the VNC WebSocket port to cause a denial of service during the WebSocket handshake prior to the VNC client authentication.
A flaw was found in QEMU. If the QIOChannelWebsock object is freed whi ...
EPSS
7.5 High
CVSS3