Home

Description

A flaw was found in QEMU's virtio-blk device. The issue arises because the device does not properly validate the size of input descriptors before writing data. A malicious guest with high privileges could exploit this vulnerability by submitting a malformed virtio-blk SCSI request, leading to an out-of-bounds write in the host heap memory and a potential denial of service (DoS) for the QEMU process.

PUBLISHED Reserved 2026-05-26 | Published 2026-06-12 | Updated 2026-06-12 | Assigner redhat




MEDIUM: 6.7CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:H

Problem types

Heap-based Buffer Overflow

Product status

Default status
unaffected

1.1.0 (semver)
affected

Default status
affected

Default status
affected

Default status
affected

Default status
affected

Default status
affected

Default status
affected

Default status
affected

Default status
affected

Timeline

2026-06-12:Reported to Red Hat.
2026-05-26:Made public.

Credits

Red Hat would like to thank Feifan Qian <bea1e@proton.me> for reporting this issue.

References

access.redhat.com/security/cve/CVE-2026-48914 vdb-entry

bugzilla.redhat.com/show_bug.cgi?id=2488283 (RHBZ#2488283) issue-tracking

lore.kernel.org/...0526154957.1741622-1-stefanha@redhat.com/

cve.org (CVE-2026-48914)

nvd.nist.gov (CVE-2026-48914)

Download JSON