Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2026:39311

Опубликовано: 15 июл. 2026
Источник: rocky
Оценка: Low

Описание

Low: qemu-kvm security update

Kernel-based Virtual Machine (KVM) is a full virtualization solution for Linux on a variety of architectures. The qemu-kvm packages provide the user-space component for running virtual machines that use KVM.

Security Fix(es):

  • qemu-kvm: Heap buffer overflow in virtio-blk SCSI request handling (CVE-2026-48914)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 9

НаименованиеАрхитектураРелизRPM
qemu-guest-agentx86_6417.el9_8.4qemu-guest-agent-10.1.0-17.el9_8.4.x86_64.rpm
qemu-imgx86_6417.el9_8.4qemu-img-10.1.0-17.el9_8.4.x86_64.rpm
qemu-kvmx86_6417.el9_8.4qemu-kvm-10.1.0-17.el9_8.4.x86_64.rpm
qemu-kvm-audio-pax86_6417.el9_8.4qemu-kvm-audio-pa-10.1.0-17.el9_8.4.x86_64.rpm
qemu-kvm-block-blkiox86_6417.el9_8.4qemu-kvm-block-blkio-10.1.0-17.el9_8.4.x86_64.rpm
qemu-kvm-block-curlx86_6417.el9_8.4qemu-kvm-block-curl-10.1.0-17.el9_8.4.x86_64.rpm
qemu-kvm-block-rbdx86_6417.el9_8.4qemu-kvm-block-rbd-10.1.0-17.el9_8.4.x86_64.rpm
qemu-kvm-commonx86_6417.el9_8.4qemu-kvm-common-10.1.0-17.el9_8.4.x86_64.rpm
qemu-kvm-corex86_6417.el9_8.4qemu-kvm-core-10.1.0-17.el9_8.4.x86_64.rpm
qemu-kvm-device-display-virtio-gpux86_6417.el9_8.4qemu-kvm-device-display-virtio-gpu-10.1.0-17.el9_8.4.x86_64.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 6.7
ubuntu
около 2 месяцев назад

A flaw was found in QEMU's virtio-blk device. The issue arises because the device does not properly validate the size of input descriptors before writing data. A malicious guest with high privileges could exploit this vulnerability by submitting a malformed virtio-blk SCSI request, leading to an out-of-bounds write in the host heap memory and a potential denial of service (DoS) for the QEMU process.

CVSS3: 6.7
redhat
2 месяца назад

A flaw was found in QEMU's virtio-blk device. The issue arises because the device does not properly validate the size of input descriptors before writing data. A malicious guest with high privileges could exploit this vulnerability by submitting a malformed virtio-blk SCSI request, leading to an out-of-bounds write in the host heap memory and a potential denial of service (DoS) for the QEMU process.

CVSS3: 6.7
nvd
около 2 месяцев назад

A flaw was found in QEMU's virtio-blk device. The issue arises because the device does not properly validate the size of input descriptors before writing data. A malicious guest with high privileges could exploit this vulnerability by submitting a malformed virtio-blk SCSI request, leading to an out-of-bounds write in the host heap memory and a potential denial of service (DoS) for the QEMU process.

CVSS3: 6.7
msrc
около 1 месяца назад

Qemu-kvm: heap buffer overflow in virtio-blk scsi request handling

CVSS3: 6.7
debian
около 2 месяцев назад

A flaw was found in QEMU's virtio-blk device. The issue arises because ...