cbcvebase.
CVE-2025-8860
published 2026-02-18

CVE-2025-8860: A flaw was found in QEMU in the uefi-vars virtual device. When the guest writes to register UEFI_VARS_REG_BUFFER_SIZE, the .write callback `uefi_vars_write` is…

PriorityP413low3.3CVSS 3.1
AVLACLPRLUINSUCLINAN
EPSS
0.15%
4.4th percentile
A flaw was found in QEMU in the uefi-vars virtual device. When the guest writes to register UEFI_VARS_REG_BUFFER_SIZE, the .write callback `uefi_vars_write` is invoked. The function allocates a heap buffer without zeroing the memory, leaving the buffer filled with residual data from prior allocations. When the guest later reads from register UEFI_VARS_REG_PIO_BUFFER_TRANSFER, the .read callback `uefi_vars_read` returns leftover metadata or other sensitive process memory from the previously allocated buffer, leading to an information disclosure vulnerability.

Affected

3 ranges
VendorProductVersion rangeFixed in
debianqemu< qemu 1:10.0.3+ds-4 (forky)qemu 1:10.0.3+ds-4 (forky)
qemuqemu>= 0 < 1:10.0.3+ds-41:10.0.3+ds-4
qemuqemu>= 0 < 1:10.0.3+ds-41:10.0.3+ds-4

CVSS provenance

nvdv3.13.3LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
osv3.3LOW
vendor_debian3.3LOW
vendor_redhat3.3LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.