Qemu
421 known vulnerabilities
Top Products
hw/pci/pcie_sriov.c in QEMU through 10.0.3 mishandles the VF Enable bit write mask, a related issue to CVE-2024-26327.
hw/pci/pcie_sriov.c in QEMU through 10.0.3 has a migration state inconsistency, a related issue to CVE-2024-26327.
A heap buffer overflow was found in the virtio-snd device in QEMU. When reading input audio in the virtio-snd input call
A heap-based buffer overflow was found in the SDHCI device emulation of QEMU. The bug is triggered when both `s->data_co
A use-after-free vulnerability was found in the QEMU LSI53C895A SCSI Host Bus Adapter emulation. This issue can lead to
A flaw was found in QEMU. An assertion failure was present in the usb_ep_get() function in hw/net/core.c when trying to
A flaw was found in the virtio-net device in QEMU. When enabling the RSS feature on the virtio-net network card, the ind
A flaw was found in QEMU. An assertion failure was present in the update_sctp_checksum() function in hw/net/net_tx_pkt.c
QEMU before 8.2.0 has an integer underflow, and resultant buffer overflow, via a TI command when an expected non-DMA tra
An issue was discovered in QEMU 7.1.0 through 8.2.1. register_vfs in hw/pci/pcie_sriov.c does not set NumVFs to PCI_SRIO
An issue was discovered in QEMU 7.1.0 through 8.2.1. register_vfs in hw/pci/pcie_sriov.c mishandles the situation where
A flaw was found in the QEMU built-in VNC server while processing ClientCutText messages. The qemu_clipboard_request() f
A stack based buffer overflow was found in the virtio-net device of QEMU. This issue occurs when flushing TX in the virt
A flaw was found in the 9p passthrough filesystem (9pfs) implementation in QEMU. The 9pfs server did not prohibit openin
A bug in QEMU could cause a guest I/O operation otherwise addressed to an arbitrary disk offset to be targeted to offset
A flaw was found in QEMU. The async nature of hot-unplug enables a race scenario where the net device backend is cleared
A flaw was found in the QEMU built-in VNC server while processing ClientCutText messages. A wrong exit condition may lea
This CVE exists because of an incomplete fix for CVE-2021-3750. More specifically, the qemu-kvm package as released for
QEMU through 8.0.0 could trigger a division by zero in scsi_disk_reset in hw/scsi/scsi-disk.c because scsi_disk_emulate_
An issue was discovered in TCG Accelerator in QEMU 4.2.0, allows local attackers to execute arbitrary code, escalate pri
The hardware emulation in the of_dpa_cmd_add_l2_flood of rocker device model in QEMU, as used in 7.0.0 and earlier, allo
QEMU through 8.0.4 accesses a NULL pointer in nvme_directive_receive in hw/nvme/ctrl.c because there is no check for whe
A heap out-of-bounds memory read flaw was found in the virtual nvme device in QEMU. The QEMU process does not validate a
A flaw was found in the QEMU virtual crypto device while handling data encryption/decryption requests in virtio_crypto_h
A DMA reentrancy issue leading to a use-after-free error was found in the e1000e NIC emulation code in QEMU. This issue
A flaw was found in the 9p passthrough filesystem (9pfs) implementation in QEMU. When a local user in the guest writes a
A flaw was found in the QEMU built-in VNC server. When a client connects to the VNC server, QEMU checks whether the curr
A flaw was found in the QEMU Guest Agent service for Windows. A local unprivileged user may be able to manipulate the QE
A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device. This flaw allows a crafted guest driver
A vulnerability in the lsi53c895a device affects the latest version of qemu. A DMA-MMIO reentrancy problem may lead to m
An integer overflow and buffer overflow issues were found in the ACPI Error Record Serialization Table (ERST) device of
An out-of-bounds read flaw was found in the QXL display device emulation in QEMU. The qxl_phys2virt() function does not
An off-by-one read/write issue was found in the SDHCI device of QEMU. It occurs when reading/writing the Buffer Data Por
An integer underflow issue was found in the QEMU VNC server while processing ClientCutText messages in the extended form
Qemu before 2.0 block driver for Hyper-V VHDX Images is vulnerable to infinite loops and other potential issues when cal
Qemu before 1.6.2 block diver for the various disk image formats used by Bochs and for the QCOW version 2 format, are vu
QEMU before 2.0.0 block drivers for CLOOP, QCOW2 version 2 and various other image formats are vulnerable to potential m
A DMA reentrancy issue was found in the Tulip device emulation in QEMU. When Tulip reads or writes to the rx/tx descript
A flaw was found in the QEMU virtio-fs shared file system daemon (virtiofsd) implementation. This flaw is strictly relat
A use-after-free vulnerability was found in the LSI53C895A SCSI Host Bus Adapter emulation of QEMU. The flaw occurs whil
A deadlock issue was found in the AHCI controller device of QEMU. It occurs on a software reset (ahci_reset_port) while
A DMA reentrancy issue was found in the NVM Express Controller (NVME) emulation in QEMU. This CVE is similar to CVE-2021
A NULL pointer dereference issue was found in the ACPI code of QEMU. A malicious, privileged user within the guest could
An infinite loop flaw was found in the USB xHCI controller emulation of QEMU while computing the length of the Transfer
softmmu/physmem.c in QEMU through 7.0.0 can perform an uninitialized read on the translate_fail path, leading to an io_r
A stack overflow vulnerability was found in the Intel HD Audio device (intel-hda) of QEMU. A malicious guest could use t
A DMA reentrancy issue was found in the USB EHCI controller emulation of QEMU. EHCI does not verify if the Buffer Pointe
A flaw was found in the QXL display device emulation in QEMU. A double fetch of guest controlled values `cursor->header.
A flaw was found in the QXL display device emulation in QEMU. An integer overflow in the cursor_alloc() function can lea
It was discovered that the update for the virt:rhel module in the RHSA-2020:4676 (https://access.redhat.com/errata/RHSA-
Frequently Asked Questions
How many CVEs affect Qemu?
Qemu has 421 CVE records in our database, including 13 critical and 123 high severity vulnerabilities.
What are the most severe Qemu vulnerabilities?
Qemu has 13 critical severity (CVSS 9.0+) and 123 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Qemu vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Qemu products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Qemu Vulnerabilities
CyberStrike scans your infrastructure for Qemu vulnerabilities and provides real-time remediation guidance.
Get Started