Junglewise Threat Intelligence

CVE-2026-3196: QEMU virtio-snd integer overflow in PCM_INFO requests

CVE-2026-3196 · Severity: medium · CVSS 5.5 · Published 2026-06-19

Technologies: Red Hat Enterprise Linux 8, QEMU Project Qemu, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 10. Vendors: Red Hat.

Executive brief

A security vulnerability has been identified in QEMU, a widely used virtualization tool that allows computers to run multiple operating systems simultaneously. A malicious user within a virtual machine could exploit this flaw to crash the host system or exhaust its memory resources. This results in a denial of service, potentially disrupting other virtual machines and services running on the same physical hardware.

Technical details

An integer overflow vulnerability exists in the virtio-snd device component of QEMU during the processing of PCM_INFO requests. The flaw is triggered when a guest provides out-of-bounds stream counts, which leads to improper calculation of memory requirements. An attacker with local access to a guest virtual machine can exploit this to trigger unbounded memory allocation on the host system, resulting in a denial of service (DoS). The vulnerability is tracked as CWE-190 and affects QEMU versions 8.2.0 through 10.2.1. A fix has been committed to the upstream QEMU repository.

Affected products

  • QEMU Project QEMU 8.2.0 to 10.2.1
  • Red Hat Red Hat Enterprise Linux 10
  • Red Hat Red Hat Enterprise Linux 9
  • Red Hat Red Hat Enterprise Linux 8

Timeline

  • 2026-03-02: disclosed: Initial report in Red Hat Bugzilla
  • 2026-06-19: advisory: NVD publication date

References

Related threats