Description
hw/pci/pcie_sriov.c in QEMU through 10.0.3 mishandles the VF Enable bit write mask, a related issue to CVE-2024-26327.
CVSS vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:LExploitability: 2.8 | Impact: 2.5Attack Vector: Adjacent
Complexity: Low
Privileges: None
User Interaction: None
Scope: Unchanged
Confidentiality: None
Integrity: Low
Availability: Low
Affected Packages3 packages
🔴Vulnerability Details
3GHSAGHSA-c2q6-w8rj-wvhw: hw/pci/pcie_sriov↗2025-07-25 ▶ CVEListCVE-2025-54567: hw/pci/pcie_sriov↗2025-07-25 ▶ OSVCVE-2025-54567: hw/pci/pcie_sriov↗2025-07-25 ▶ 📋Vendor Advisories
3Red Hatqemu-kvm: QEMU SR-IOV Enable Mask Vulnerability↗2025-07-25 ▶ Microsofthw/pci/pcie_sriov.c in QEMU through 10.0.3 mishandles the VF Enable bit write mask, a related issue to CVE-2024-26327.↗2025-07-08 ▶ DebianCVE-2025-54567: qemu - hw/pci/pcie_sriov.c in QEMU through 10.0.3 mishandles the VF Enable bit write ma...↗2025 ▶