Логотип exploitDog
bind:"CVE-2025-11234"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2025-11234"

Количество 10

Количество 10

ubuntu логотип

CVE-2025-11234

4 месяца назад

A flaw was found in QEMU. If the QIOChannelWebsock object is freed while it is waiting to complete a handshake, a GSource is leaked. This can lead to the callback firing later on and triggering a use-after-free in the use of the channel. This can be abused by a malicious client with network access to the VNC WebSocket port to cause a denial of service during the WebSocket handshake prior to the VNC client authentication.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2025-11234

4 месяца назад

A flaw was found in QEMU. If the QIOChannelWebsock object is freed while it is waiting to complete a handshake, a GSource is leaked. This can lead to the callback firing later on and triggering a use-after-free in the use of the channel. This can be abused by a malicious client with network access to the VNC WebSocket port to cause a denial of service during the WebSocket handshake prior to the VNC client authentication.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2025-11234

4 месяца назад

Qemu-kvm: vnc websocket handshake use-after-free

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2025-11234

4 месяца назад

A flaw was found in QEMU. If the QIOChannelWebsock object is freed whi ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-hm8v-8c3v-cxfq

4 месяца назад

A flaw was found in QEMU. If the QIOChannelWebsock object is freed while it is waiting to complete a handshake, a GSource is leaked. This can lead to the callback firing later on and triggering a use-after-free in the use of the channel. This can be abused by a malicious client with network access to the VNC WebSocket port to cause a denial of service during the WebSocket handshake prior to the VNC client authentication.

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2025-16063

4 месяца назад

Уязвимость эмулятора аппаратного обеспечения QEMU, связанная с использованием памяти после её освобождения, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2025:20171-1

около 2 месяцев назад

Security update for qemu

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0288-1

12 дней назад

Security update for qemu

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0022-1

около 1 месяца назад

Security update for qemu

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0039-1

около 1 месяца назад

Security update for qemu

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-11234

A flaw was found in QEMU. If the QIOChannelWebsock object is freed while it is waiting to complete a handshake, a GSource is leaked. This can lead to the callback firing later on and triggering a use-after-free in the use of the channel. This can be abused by a malicious client with network access to the VNC WebSocket port to cause a denial of service during the WebSocket handshake prior to the VNC client authentication.

CVSS3: 7.5
0%
Низкий
4 месяца назад
nvd логотип
CVE-2025-11234

A flaw was found in QEMU. If the QIOChannelWebsock object is freed while it is waiting to complete a handshake, a GSource is leaked. This can lead to the callback firing later on and triggering a use-after-free in the use of the channel. This can be abused by a malicious client with network access to the VNC WebSocket port to cause a denial of service during the WebSocket handshake prior to the VNC client authentication.

CVSS3: 7.5
0%
Низкий
4 месяца назад
msrc логотип
CVE-2025-11234

Qemu-kvm: vnc websocket handshake use-after-free

CVSS3: 7.5
0%
Низкий
4 месяца назад
debian логотип
CVE-2025-11234

A flaw was found in QEMU. If the QIOChannelWebsock object is freed whi ...

CVSS3: 7.5
0%
Низкий
4 месяца назад
github логотип
GHSA-hm8v-8c3v-cxfq

A flaw was found in QEMU. If the QIOChannelWebsock object is freed while it is waiting to complete a handshake, a GSource is leaked. This can lead to the callback firing later on and triggering a use-after-free in the use of the channel. This can be abused by a malicious client with network access to the VNC WebSocket port to cause a denial of service during the WebSocket handshake prior to the VNC client authentication.

CVSS3: 7.5
0%
Низкий
4 месяца назад
fstec логотип
BDU:2025-16063

Уязвимость эмулятора аппаратного обеспечения QEMU, связанная с использованием памяти после её освобождения, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
0%
Низкий
4 месяца назад
suse-cvrf логотип
openSUSE-SU-2025:20171-1

Security update for qemu

около 2 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:0288-1

Security update for qemu

12 дней назад
suse-cvrf логотип
SUSE-SU-2026:0022-1

Security update for qemu

около 1 месяца назад
suse-cvrf логотип
SUSE-SU-2026:0039-1

Security update for qemu

около 1 месяца назад

Уязвимостей на страницу