Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 10

Количество 10

github логотип

GHSA-4hmh-vx7h-h98p

около 2 месяцев назад

A flaw was found in QEMU's virtio-blk device. The issue arises because the device does not properly validate the size of input descriptors before writing data. A malicious guest with high privileges could exploit this vulnerability by submitting a malformed virtio-blk SCSI request, leading to an out-of-bounds write in the host heap memory and a potential denial of service (DoS) for the QEMU process.

CVSS3: 6.7
EPSS: Низкий
ubuntu логотип

CVE-2026-48914

около 2 месяцев назад

A flaw was found in QEMU's virtio-blk device. The issue arises because the device does not properly validate the size of input descriptors before writing data. A malicious guest with high privileges could exploit this vulnerability by submitting a malformed virtio-blk SCSI request, leading to an out-of-bounds write in the host heap memory and a potential denial of service (DoS) for the QEMU process.

CVSS3: 6.7
EPSS: Низкий
redhat логотип

CVE-2026-48914

2 месяца назад

A flaw was found in QEMU's virtio-blk device. The issue arises because the device does not properly validate the size of input descriptors before writing data. A malicious guest with high privileges could exploit this vulnerability by submitting a malformed virtio-blk SCSI request, leading to an out-of-bounds write in the host heap memory and a potential denial of service (DoS) for the QEMU process.

CVSS3: 6.7
EPSS: Низкий
nvd логотип

CVE-2026-48914

около 2 месяцев назад

A flaw was found in QEMU's virtio-blk device. The issue arises because the device does not properly validate the size of input descriptors before writing data. A malicious guest with high privileges could exploit this vulnerability by submitting a malformed virtio-blk SCSI request, leading to an out-of-bounds write in the host heap memory and a potential denial of service (DoS) for the QEMU process.

CVSS3: 6.7
EPSS: Низкий
msrc логотип

CVE-2026-48914

около 1 месяца назад

Qemu-kvm: heap buffer overflow in virtio-blk scsi request handling

CVSS3: 6.7
EPSS: Низкий
debian логотип

CVE-2026-48914

около 2 месяцев назад

A flaw was found in QEMU's virtio-blk device. The issue arises because ...

CVSS3: 6.7
EPSS: Низкий
rocky логотип

RLSA-2026:39311

16 дней назад

Low: qemu-kvm security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-39311

18 дней назад

ELSA-2026-39311: qemu-kvm security update (LOW)

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21253-1

24 дня назад

Security update for qemu

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3038-1

16 дней назад

Security update for qemu

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4hmh-vx7h-h98p

A flaw was found in QEMU's virtio-blk device. The issue arises because the device does not properly validate the size of input descriptors before writing data. A malicious guest with high privileges could exploit this vulnerability by submitting a malformed virtio-blk SCSI request, leading to an out-of-bounds write in the host heap memory and a potential denial of service (DoS) for the QEMU process.

CVSS3: 6.7
0%
Низкий
около 2 месяцев назад
ubuntu логотип
CVE-2026-48914

A flaw was found in QEMU's virtio-blk device. The issue arises because the device does not properly validate the size of input descriptors before writing data. A malicious guest with high privileges could exploit this vulnerability by submitting a malformed virtio-blk SCSI request, leading to an out-of-bounds write in the host heap memory and a potential denial of service (DoS) for the QEMU process.

CVSS3: 6.7
0%
Низкий
около 2 месяцев назад
redhat логотип
CVE-2026-48914

A flaw was found in QEMU's virtio-blk device. The issue arises because the device does not properly validate the size of input descriptors before writing data. A malicious guest with high privileges could exploit this vulnerability by submitting a malformed virtio-blk SCSI request, leading to an out-of-bounds write in the host heap memory and a potential denial of service (DoS) for the QEMU process.

CVSS3: 6.7
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-48914

A flaw was found in QEMU's virtio-blk device. The issue arises because the device does not properly validate the size of input descriptors before writing data. A malicious guest with high privileges could exploit this vulnerability by submitting a malformed virtio-blk SCSI request, leading to an out-of-bounds write in the host heap memory and a potential denial of service (DoS) for the QEMU process.

CVSS3: 6.7
0%
Низкий
около 2 месяцев назад
msrc логотип
CVE-2026-48914

Qemu-kvm: heap buffer overflow in virtio-blk scsi request handling

CVSS3: 6.7
0%
Низкий
около 1 месяца назад
debian логотип
CVE-2026-48914

A flaw was found in QEMU's virtio-blk device. The issue arises because ...

CVSS3: 6.7
0%
Низкий
около 2 месяцев назад
rocky логотип
RLSA-2026:39311

Low: qemu-kvm security update

0%
Низкий
16 дней назад
oracle-oval логотип
ELSA-2026-39311

ELSA-2026-39311: qemu-kvm security update (LOW)

18 дней назад
suse-cvrf логотип
openSUSE-SU-2026:21253-1

Security update for qemu

24 дня назад
suse-cvrf логотип
SUSE-SU-2026:3038-1

Security update for qemu

16 дней назад

Уязвимостей на страницу