cbcvebase.
CVE-2025-14876
published 2026-02-18

CVE-2025-14876: A flaw was found in the virtio-crypto device of QEMU. A malicious guest operating system can exploit a missing length limit in the AKCIPHER path, leading to…

PriorityP423medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.14%
3.5th percentile
A flaw was found in the virtio-crypto device of QEMU. A malicious guest operating system can exploit a missing length limit in the AKCIPHER path, leading to uncontrolled memory allocation. This can result in a denial of service (DoS) on the host system by causing the QEMU process to terminate unexpectedly.

Affected

6 ranges
VendorProductVersion rangeFixed in
debianqemu< qemu 1:10.2.1+ds-1 (forky)qemu 1:10.2.1+ds-1 (forky)
qemuqemu>= 0 < 1:10.0.8+ds-0+deb13u11:10.0.8+ds-0+deb13u1
qemuqemu>= 0 < 1:10.2.1+ds-11:10.2.1+ds-1
qemuqemu>= 0 < 1:6.2+dfsg-2ubuntu6.281:6.2+dfsg-2ubuntu6.28
qemuqemu>= 0 < 1:8.2.2+ds-0ubuntu1.131:8.2.2+ds-0ubuntu1.13
qemuqemu>= 0 < 1:10.1.0+ds-5ubuntu2.41:10.1.0+ds-5ubuntu2.4

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.