CVE-2024-26327
published 2024-02-19CVE-2024-26327: An issue was discovered in QEMU 7.1.0 through 8.2.1. register_vfs in hw/pci/pcie_sriov.c mishandles the situation where a guest writes NumVFs greater than…
PriorityP421medium5.3CVSS 3.1
AVAACHPRNUINSUCNINAH
EPSS
0.53%
41.6th percentile
An issue was discovered in QEMU 7.1.0 through 8.2.1. register_vfs in hw/pci/pcie_sriov.c mishandles the situation where a guest writes NumVFs greater than TotalVFs, leading to a buffer overflow in VF implementations.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | qemu | < qemu 1:7.2+dfsg-7+deb12u6 (bookworm) | qemu 1:7.2+dfsg-7+deb12u6 (bookworm) |
| debian | qemu | < qemu 1:10.0.3+ds-1 (forky) | qemu 1:10.0.3+ds-1 (forky) |
| msrc | azl3_qemu_8.2.0-16_on_azure_linux_3.0 | — | — |
| msrc | azl3_qemu_8.2.0-17_on_azure_linux_3.0 | — | — |
| msrc | cbl2_qemu_6.2.0-26_on_cbl_mariner_2.0 | — | — |
| qemu | qemu | <= 10.0.3 | — |
| qemu | qemu | >= 0 < 1:7.2+dfsg-7+deb12u6 | 1:7.2+dfsg-7+deb12u6 |
| qemu | qemu | >= 0 < 1:10.0.2+ds-2+deb13u1 | 1:10.0.2+ds-2+deb13u1 |
| qemu | qemu | >= 0 < 1:8.2.3+ds-1 | 1:8.2.3+ds-1 |
| qemu | qemu | >= 0 < 1:10.0.3+ds-1 | 1:10.0.3+ds-1 |
| qemu | qemu | >= 0 < 1:8.2.3+ds-1 | 1:8.2.3+ds-1 |
| qemu | qemu | >= 0 < 1:8.2.2+ds-0ubuntu1.2 | 1:8.2.2+ds-0ubuntu1.2 |
| qemu | qemu | 10.0.0 – 10.0.3 | — |
| qemu | qemu | 7.1.0 – 8.2.1 | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
osv5.3MEDIUM
vendor_debian5.3LOW
vendor_msrc5.3MEDIUM
vendor_redhat5.3MEDIUM
vendor_ubuntu5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-399m-rf4f-w5x4: hw/pci/pcie_sriov
ghsa_unreviewed·2025-07-25·CVSS 5.3
CVE-2025-54566 [MEDIUM] CWE-642 GHSA-399m-rf4f-w5x4: hw/pci/pcie_sriov
hw/pci/pcie_sriov.c in QEMU through 10.0.3 has a migration state inconsistency, a related issue to CVE-2024-26327.
GHSA
GHSA-c2q6-w8rj-wvhw: hw/pci/pcie_sriov
ghsa_unreviewed·2025-07-25·CVSS 5.3
CVE-2025-54567 [MEDIUM] CWE-684 GHSA-c2q6-w8rj-wvhw: hw/pci/pcie_sriov
hw/pci/pcie_sriov.c in QEMU through 10.0.3 mishandles the VF Enable bit write mask, a related issue to CVE-2024-26327.
OSV
CVE-2025-54566: hw/pci/pcie_sriov
osv·2025-07-25·CVSS 5.3
CVE-2025-54566 [MEDIUM] CVE-2025-54566: hw/pci/pcie_sriov
hw/pci/pcie_sriov.c in QEMU through 10.0.3 has a migration state inconsistency, a related issue to CVE-2024-26327.
OSV
CVE-2025-54567: hw/pci/pcie_sriov
osv·2025-07-25·CVSS 5.3
CVE-2025-54567 [MEDIUM] CVE-2025-54567: hw/pci/pcie_sriov
hw/pci/pcie_sriov.c in QEMU through 10.0.3 mishandles the VF Enable bit write mask, a related issue to CVE-2024-26327.
OSV
qemu vulnerabilities
osv·2024-08-22·CVSS 5.3
CVE-2024-26327 [MEDIUM] qemu vulnerabilities
qemu vulnerabilities
It was discovered that QEMU did not properly handle certain memory
operations, which could result in a buffer overflow. An attacker could
potentially use this issue to cause a denial of service. (CVE-2024-26327)
It was discovered that QEMU did not properly handle certain memory
operations, which could result in an out-of-bounds memory access. An
attacker could potentially use this issue to cause a denial of service.
(CVE-2024-26328)
OSV
CVE-2024-26327: An issue was discovered in QEMU 7
osv·2024-02-19·CVSS 5.3
CVE-2024-26327 [MEDIUM] CVE-2024-26327: An issue was discovered in QEMU 7
An issue was discovered in QEMU 7.1.0 through 8.2.1. register_vfs in hw/pci/pcie_sriov.c mishandles the situation where a guest writes NumVFs greater than TotalVFs, leading to a buffer overflow in VF implementations.
GHSA
GHSA-7m48-vw34-vw84: An issue was discovered in QEMU 7
ghsa_unreviewed·2024-02-19
CVE-2024-26327 [MEDIUM] CWE-122 GHSA-7m48-vw34-vw84: An issue was discovered in QEMU 7
An issue was discovered in QEMU 7.1.0 through 8.2.1. register_vfs in hw/pci/pcie_sriov.c mishandles the situation where a guest writes NumVFs greater than TotalVFs, leading to a buffer overflow in VF implementations.
Red Hat
qemu-kvm: QEMU SR-IOV Migration Inconsistency
vendor_redhat·2025-07-25·CVSS 5.3
CVE-2025-54566 [MEDIUM] CWE-642 qemu-kvm: QEMU SR-IOV Migration Inconsistency
qemu-kvm: QEMU SR-IOV Migration Inconsistency
hw/pci/pcie_sriov.c in QEMU through 10.0.3 has a migration state inconsistency, a related issue to CVE-2024-26327.
A flaw was found in QEMU. A migration state inconsistency within the pcie_sriov emulation code allows an attacker with adjacent network access to trigger unexpected behavior. This condition arises from a state mismatch during migration processes, which can potentially lead to resource exhaustion. The vulnerability allows for exploitation via a malformed migration data stream. This issue can result in a denial of service.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespre
Red Hat
qemu-kvm: QEMU SR-IOV Enable Mask Vulnerability
vendor_redhat·2025-07-25·CVSS 5.3
CVE-2025-54567 [MEDIUM] CWE-684 qemu-kvm: QEMU SR-IOV Enable Mask Vulnerability
qemu-kvm: QEMU SR-IOV Enable Mask Vulnerability
hw/pci/pcie_sriov.c in QEMU through 10.0.3 mishandles the VF Enable bit write mask, a related issue to CVE-2024-26327.
A flaw was found in QEMU. The PCIE SR-IOV emulation within QEMU incorrectly handles write masks for the VF Enable bit. This vulnerability allows an attacker with adjacent network access to trigger unexpected behavior. Mishandling occurs due to a logic error in hw/pci/pcie_sriov.c. Exploitation involves crafting a malicious network packet that can result in a denial of service.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Pac
Microsoft
hw/pci/pcie_sriov.c in QEMU through 10.0.3 has a migration state inconsistency, a related issue to CVE-2024-26327.
vendor_msrc·2025-07-08·CVSS 4.2
CVE-2025-54566 [MEDIUM] CWE-642 hw/pci/pcie_sriov.c in QEMU through 10.0.3 has a migration state inconsistency, a related issue to CVE-2024-26327.
hw/pci/pcie_sriov.c in QEMU through 10.0.3 has a migration state inconsistency, a related issue to CVE-2024-26327.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
mitre: mitre
Customer Action Required: Yes
Microsoft
hw/pci/pcie_sriov.c in QEMU through 10.0.3 mishandles the VF Enable bit write mask, a related issue to CVE-2024-26327.
vendor_msrc·2025-07-08·CVSS 4.2
CVE-2025-54567 [MEDIUM] CWE-684 hw/pci/pcie_sriov.c in QEMU through 10.0.3 mishandles the VF Enable bit write mask, a related issue to CVE-2024-26327.
hw/pci/pcie_sriov.c in QEMU through 10.0.3 mishandles the VF Enable bit write mask, a related issue to CVE-2024-26327.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
mitre: mitre
Customer Action Required: Y
Debian
CVE-2025-54567: qemu - hw/pci/pcie_sriov.c in QEMU through 10.0.3 mishandles the VF Enable bit write ma...
vendor_debian·2025·CVSS 5.3
CVE-2025-54567 [MEDIUM] CVE-2025-54567: qemu - hw/pci/pcie_sriov.c in QEMU through 10.0.3 mishandles the VF Enable bit write ma...
hw/pci/pcie_sriov.c in QEMU through 10.0.3 mishandles the VF Enable bit write mask, a related issue to CVE-2024-26327.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 1:10.0.3+ds-1)
sid: resolved (fixed in 1:10.0.3+ds-1)
trixie: resolved (fixed in 1:10.0.2+ds-2+deb13u1)
Debian
CVE-2025-54566: qemu - hw/pci/pcie_sriov.c in QEMU through 10.0.3 has a migration state inconsistency, ...
vendor_debian·2025·CVSS 5.3
CVE-2025-54566 [MEDIUM] CVE-2025-54566: qemu - hw/pci/pcie_sriov.c in QEMU through 10.0.3 has a migration state inconsistency, ...
hw/pci/pcie_sriov.c in QEMU through 10.0.3 has a migration state inconsistency, a related issue to CVE-2024-26327.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 1:10.0.3+ds-1)
sid: resolved (fixed in 1:10.0.3+ds-1)
trixie: resolved (fixed in 1:10.0.2+ds-2+deb13u1)
Ubuntu
QEMU vulnerabilities
vendor_ubuntu·2024-08-22·CVSS 5.3
CVE-2024-26327 [MEDIUM] QEMU vulnerabilities
Title: QEMU vulnerabilities
Summary: Several security issues were fixed in QEMU.
It was discovered that QEMU did not properly handle certain memory
operations, which could result in a buffer overflow. An attacker could
potentially use this issue to cause a denial of service. (CVE-2024-26327)
It was discovered that QEMU did not properly handle certain memory
operations, which could result in an out-of-bounds memory access. An
attacker could potentially use this issue to cause a denial of service.
(CVE-2024-26328)
Instructions: After a standard system update you need to restart all QEMU virtual
machines to make all the necessary changes.
Red Hat
qemu-kvm: pcie: improper validation of NumVFs leads to buffer overflow
vendor_redhat·2024-02-19·CVSS 5.3
CVE-2024-26327 [MEDIUM] CWE-120 qemu-kvm: pcie: improper validation of NumVFs leads to buffer overflow
qemu-kvm: pcie: improper validation of NumVFs leads to buffer overflow
An issue was discovered in QEMU 7.1.0 through 8.2.1. register_vfs in hw/pci/pcie_sriov.c mishandles the situation where a guest writes NumVFs greater than TotalVFs, leading to a buffer overflow in VF implementations.
A flaw was found in the SR/IOV emulation support of QEMU. The register_vfs() function in hw/pci/pcie_sriov.c mishandled the situation where a guest writes NumVFs greater than TotalVFs, leading to a buffer overflow in VF (Virtual Function) implementations. This flaw allows a malicious guest to crash QEMU and cause a denial of service condition.
Statement: The `qemu-kvm` versions, as shipped with Red Hat Enterprise Linux 6, 7, 8 and RHEL Advanced Virtualization, are not affected by this CVE as they did not
Microsoft
An issue was discovered in QEMU 7.1.0 through 8.2.1. register_vfs in hw/pci/pcie_sriov.c mishandles the situation where a guest writes NumVFs greater than TotalVFs, leading to a buffer overflow in VF
vendor_msrc·2024-02-13·CVSS 5.3
CVE-2024-26327 [MEDIUM] CWE-787 An issue was discovered in QEMU 7.1.0 through 8.2.1. register_vfs in hw/pci/pcie_sriov.c mishandles the situation where a guest writes NumVFs greater than TotalVFs, leading to a buffer overflow in VF
An issue was discovered in QEMU 7.1.0 through 8.2.1. register_vfs in hw/pci/pcie_sriov.c mishandles the situation where a guest writes NumVFs greater than TotalVFs, leading to a buffer overflow in VF implementations.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we
Debian
CVE-2024-26327: qemu - An issue was discovered in QEMU 7.1.0 through 8.2.1. register_vfs in hw/pci/pcie...
vendor_debian·2024·CVSS 5.3
CVE-2024-26327 [MEDIUM] CVE-2024-26327: qemu - An issue was discovered in QEMU 7.1.0 through 8.2.1. register_vfs in hw/pci/pcie...
An issue was discovered in QEMU 7.1.0 through 8.2.1. register_vfs in hw/pci/pcie_sriov.c mishandles the situation where a guest writes NumVFs greater than TotalVFs, leading to a buffer overflow in VF implementations.
Scope: local
bookworm: resolved (fixed in 1:7.2+dfsg-7+deb12u6)
bullseye: resolved
forky: resolved (fixed in 1:8.2.3+ds-1)
sid: resolved (fixed in 1:8.2.3+ds-1)
trixie: resolved (fixed in 1:8.2.3+ds-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-02-19
Published