Executive brief
A security vulnerability has been identified in QEMU, a widely used virtualization tool that allows computers to run multiple operating systems simultaneously. A malicious user within a virtual machine could exploit this flaw to crash the host system or exhaust its memory resources. This results in a denial of service, potentially disrupting other virtual machines and services running on the same physical hardware.
Technical details
An integer overflow vulnerability exists in the virtio-snd device component of QEMU during the processing of PCM_INFO requests. The flaw is triggered when a guest provides out-of-bounds stream counts, which leads to improper calculation of memory requirements. An attacker with local access to a guest virtual machine can exploit this to trigger unbounded memory allocation on the host system, resulting in a denial of service (DoS). The vulnerability is tracked as CWE-190 and affects QEMU versions 8.2.0 through 10.2.1. A fix has been committed to the upstream QEMU repository.
Affected products
- QEMU Project QEMU 8.2.0 to 10.2.1
- Red Hat Red Hat Enterprise Linux 10
- Red Hat Red Hat Enterprise Linux 9
- Red Hat Red Hat Enterprise Linux 8
Timeline
- 2026-03-02: disclosed: Initial report in Red Hat Bugzilla
- 2026-06-19: advisory: NVD publication date