Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2026:1831

Опубликовано: 06 фев. 2026
Источник: rocky
Оценка: Moderate

Описание

Moderate: qemu-kvm security update

Kernel-based Virtual Machine (KVM) is a full virtualization solution for Linux on a variety of architectures. The qemu-kvm packages provide the user-space component for running virtual machines that use KVM.

Security Fix(es):

  • qemu-kvm: VNC WebSocket handshake use-after-free (CVE-2025-11234)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 10

НаименованиеАрхитектураРелизRPM
qemu-kvm-device-display-virtio-gpuaarch6414.el10_1.5qemu-kvm-device-display-virtio-gpu-10.0.0-14.el10_1.5.aarch64.rpm
qemu-kvm-audio-paaarch6414.el10_1.5qemu-kvm-audio-pa-10.0.0-14.el10_1.5.aarch64.rpm
qemu-kvm-device-usb-redirectaarch6414.el10_1.5qemu-kvm-device-usb-redirect-10.0.0-14.el10_1.5.aarch64.rpm
qemu-kvm-device-usb-hostaarch6414.el10_1.5qemu-kvm-device-usb-host-10.0.0-14.el10_1.5.aarch64.rpm
qemu-kvm-docsaarch6414.el10_1.5qemu-kvm-docs-10.0.0-14.el10_1.5.aarch64.rpm
qemu-pr-helperaarch6414.el10_1.5qemu-pr-helper-10.0.0-14.el10_1.5.aarch64.rpm
qemu-guest-agentaarch6414.el10_1.5qemu-guest-agent-10.0.0-14.el10_1.5.aarch64.rpm
qemu-kvm-device-display-virtio-gpu-pciaarch6414.el10_1.5qemu-kvm-device-display-virtio-gpu-pci-10.0.0-14.el10_1.5.aarch64.rpm
qemu-kvm-toolsaarch6414.el10_1.5qemu-kvm-tools-10.0.0-14.el10_1.5.aarch64.rpm
qemu-kvmaarch6414.el10_1.5qemu-kvm-10.0.0-14.el10_1.5.aarch64.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 7.5
ubuntu
11 месяцев назад

A flaw was found in QEMU. If the QIOChannelWebsock object is freed while it is waiting to complete a handshake, a GSource is leaked. This can lead to the callback firing later on and triggering a use-after-free in the use of the channel. This can be abused by a malicious client with network access to the VNC WebSocket port to cause a denial of service during the WebSocket handshake prior to the VNC client authentication.

CVSS3: 7.5
redhat
11 месяцев назад

A flaw was found in QEMU. If the QIOChannelWebsock object is freed while it is waiting to complete a handshake, a GSource is leaked. This can lead to the callback firing later on and triggering a use-after-free in the use of the channel. This can be abused by a malicious client with network access to the VNC WebSocket port to cause a denial of service during the WebSocket handshake prior to the VNC client authentication.

CVSS3: 7.5
nvd
11 месяцев назад

A flaw was found in QEMU. If the QIOChannelWebsock object is freed while it is waiting to complete a handshake, a GSource is leaked. This can lead to the callback firing later on and triggering a use-after-free in the use of the channel. This can be abused by a malicious client with network access to the VNC WebSocket port to cause a denial of service during the WebSocket handshake prior to the VNC client authentication.

CVSS3: 7.5
msrc
11 месяцев назад

Qemu-kvm: vnc websocket handshake use-after-free

CVSS3: 7.5
debian
11 месяцев назад

A flaw was found in QEMU. If the QIOChannelWebsock object is freed whi ...

Уязвимость RLSA-2026:1831