Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-11234

Опубликовано: 30 сент. 2025
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

A flaw was found in QEMU. If the QIOChannelWebsock object is freed while it is waiting to complete a handshake, a GSource is leaked. This can lead to the callback firing later on and triggering a use-after-free in the use of the channel. This can be abused by a malicious client with network access to the VNC WebSocket port to cause a denial of service during the WebSocket handshake prior to the VNC client authentication.

Отчет

This CVE has been rated as Moderate because it only affects the WebSocket protocol for communication (the VNC raw TCP socket is not affected) and the use of QEMU's in-process WebSocket feature is fairly niche.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6qemu-kvmNot affected
Red Hat Enterprise Linux 7qemu-kvmNot affected
Red Hat Enterprise Linux 7qemu-kvm-maAffected
Red Hat Enterprise Linux 8virt:rhel/qemu-kvmAffected
Red Hat Enterprise Linux 9qemu-kvmAffected
Red Hat Enterprise Linux 10qemu-kvmFixedRHSA-2026:183105.02.2026
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutionsqemu-kvmFixedRHSA-2026:307723.02.2026
Red Hat Enterprise Linux 9.4 Extended Update Supportqemu-kvmFixedRHSA-2025:2322817.12.2025
Red Hat Enterprise Linux 9.4 Extended Update Supportqemu-kvmFixedRHSA-2026:316524.02.2026
Red Hat OpenShift Container Platform 4.16rhcos-416.94.202601071926FixedRHSA-2026:032615.01.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=2401209qemu-kvm: VNC WebSocket handshake use-after-free

EPSS

Процентиль: 29%
0.0011
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
6 месяцев назад

A flaw was found in QEMU. If the QIOChannelWebsock object is freed while it is waiting to complete a handshake, a GSource is leaked. This can lead to the callback firing later on and triggering a use-after-free in the use of the channel. This can be abused by a malicious client with network access to the VNC WebSocket port to cause a denial of service during the WebSocket handshake prior to the VNC client authentication.

CVSS3: 7.5
nvd
6 месяцев назад

A flaw was found in QEMU. If the QIOChannelWebsock object is freed while it is waiting to complete a handshake, a GSource is leaked. This can lead to the callback firing later on and triggering a use-after-free in the use of the channel. This can be abused by a malicious client with network access to the VNC WebSocket port to cause a denial of service during the WebSocket handshake prior to the VNC client authentication.

CVSS3: 7.5
msrc
6 месяцев назад

Qemu-kvm: vnc websocket handshake use-after-free

CVSS3: 7.5
debian
6 месяцев назад

A flaw was found in QEMU. If the QIOChannelWebsock object is freed whi ...

suse-cvrf
около 2 месяцев назад

Security update for qemu

EPSS

Процентиль: 29%
0.0011
Низкий

7.5 High

CVSS3