CVE-2026-2243
published 2026-02-19CVE-2026-2243: A flaw was found in QEMU. A specially crafted VMDK image could trigger an out-of-bounds read vulnerability, potentially leading to a 12-byte leak of sensitive…
PriorityP419medium5.1CVSS 3.1
AVLACLPRNUINSUCLINAL
EPSS
0.11%
1.7th percentile
A flaw was found in QEMU. A specially crafted VMDK image could trigger an out-of-bounds read vulnerability, potentially leading to a 12-byte leak of sensitive information or a denial of service condition (DoS).
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | qemu | < qemu 1:10.2.2+ds-1 (forky) | qemu 1:10.2.2+ds-1 (forky) |
| msrc | azl3_qemu_8.2.0-27_on_azure_linux_3.0 | — | — |
| msrc | cbl2_qemu_6.2.0-26_on_cbl_mariner_2.0 | — | — |
| qemu | qemu | >= 0 < 1:10.2.2+ds-1 | 1:10.2.2+ds-1 |
| ubuntu | qemu | — | — |
CVSS provenance
nvdv3.15.1MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
osv5.1MEDIUM
vendor_ubuntu8.2HIGH
vendor_debian5.1MEDIUM
vendor_msrc5.1MEDIUM
vendor_redhat5.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
QEMU regression
vendor_ubuntu·2026-06-28·CVSS 3.8
CVE-2020-11947 [LOW] QEMU regression
Title: QEMU regression
Summary: USN-8412-1 introduced a regression in QEMU
USN-8412-1 fixed vulnerabilities QEMU. On Ubuntu 20.04 LTS, the fix for
CVE-2024-4467 was incomplete and prevented the creation of boot volumes
from qcow2 images. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Felipe Franciosi, Raphael Norwitz, and Peter Turschmid discovered that the
iSCSI block driver in QEMU incorrectly handled certain responses from an
iSCSI server. A remote attacker could possibly use this issue to cause
QEMU to crash, resulting in a denial of service, or possibly execute
arbitrary code. This issue only affected Ubuntu 14.04 LTS. (CVE-2020-1711)
It was discovered that the iSCSI block driver in QEMU incorrectly handled
certain memory operations
Ubuntu
QEMU vulnerabilities
vendor_ubuntu·2026-06-09·CVSS 3.8
CVE-2021-3416 [LOW] QEMU vulnerabilities
Title: QEMU vulnerabilities
Summary: Several security issues were fixed in QEMU.
Felipe Franciosi, Raphael Norwitz, and Peter Turschmid discovered that the
iSCSI block driver in QEMU incorrectly handled certain responses from an
iSCSI server. A remote attacker could possibly use this issue to cause QEMU
to crash, resulting in a denial of service, or possibly execute arbitrary
code. This issue only affected Ubuntu 14.04 LTS. (CVE-2020-1711)
It was discovered that the iSCSI block driver in QEMU incorrectly handled
certain memory operations, leading to a heap-based buffer over-read. An
attacker could possibly use this issue to expose sensitive information from
the host. This issue only affected Ubuntu 14.04 LTS. (CVE-2020-11947)
Ziming Zhang discovered that the SM501 display driver in QEM
Ubuntu
QEMU vulnerabilities
vendor_ubuntu·2026-04-09·CVSS 8.2
CVE-2024-6519 [HIGH] QEMU vulnerabilities
Title: QEMU vulnerabilities
Summary: Several security issues were fixed in QEMU.
It was discovered that the LSI53C895A SCSI Host Bus Adapter implementation
of QEMU incorrectly handled memory. An attacker inside the guest could
possibly use this issue to cause QEMU to crash, resulting in a denial of
service, or possibly execute arbitrary code. (CVE-2024-6519)
It was discovered that QEMU could be made to read out of bounds when
reading VMDK images. If a user or an automated system were tricked into
opening a specially crafted VMDK image, an attacker could possibly use
this issue to leak sensitive informaton or cause QEMU to crash, resulting
in a denial of service. (CVE-2026-2243)
It was discovered that the virtio-snd device implementation of QEMU could
be made to write out of bounds. An
Red Hat
qemu-kvm: Heap buffer out-of-bounds read in VMDK compressed grain parsing
vendor_redhat·2026-02-10·CVSS 5.1
CVE-2026-2243 [MEDIUM] CWE-125 qemu-kvm: Heap buffer out-of-bounds read in VMDK compressed grain parsing
qemu-kvm: Heap buffer out-of-bounds read in VMDK compressed grain parsing
A flaw was found in QEMU. A specially crafted VMDK image could trigger an out-of-bounds read vulnerability, potentially leading to a 12-byte leak of sensitive information or a denial of service condition (DoS).
A flaw was found in QEMU. A specially crafted VMDK image could trigger an out-of-bounds read vulnerability, potentially leading to a 12-byte leak of sensitive information or a denial of service condition (DoS).
Package: qemu-kvm (Red Hat Enterprise Linux 10) - Fix deferred
Package: qemu-kvm (Red Hat Enterprise Linux 6) - Out of support scope
Package: qemu-kvm (Red Hat Enterprise Linux 7) - Out of support scope
Package: qemu-kvm-ma (Red Hat Enterprise Linux 7) - Out of support scope
Package: virt:rhel/qe
Microsoft
Qemu-kvm: heap buffer out-of-bounds read in vmdk compressed grain parsing
vendor_msrc·2026-02-10·CVSS 5.1
CVE-2026-2243 [MEDIUM] CWE-125 Qemu-kvm: heap buffer out-of-bounds read in vmdk compressed grain parsing
Qemu-kvm: heap buffer out-of-bounds read in vmdk compressed grain parsing
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Debian
CVE-2026-2243: qemu - A flaw was found in QEMU. A specially crafted VMDK image could trigger an out-of...
vendor_debian·2026·CVSS 5.1
CVE-2026-2243 [MEDIUM] CVE-2026-2243: qemu - A flaw was found in QEMU. A specially crafted VMDK image could trigger an out-of...
A flaw was found in QEMU. A specially crafted VMDK image could trigger an out-of-bounds read vulnerability, potentially leading to a 12-byte leak of sensitive information or a denial of service condition (DoS).
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1:10.2.2+ds-1)
sid: resolved (fixed in 1:10.2.2+ds-1)
trixie: open
OSV
CVE-2026-2243: A flaw was found in QEMU
osv·2026-02-19·CVSS 5.1
CVE-2026-2243 [MEDIUM] CVE-2026-2243: A flaw was found in QEMU
A flaw was found in QEMU. A specially crafted VMDK image could trigger an out-of-bounds read vulnerability, potentially leading to a 12-byte leak of sensitive information or a denial of service condition (DoS).
GHSA
GHSA-cw9w-w7fx-35q6: A flaw was found in QEMU
ghsa_unreviewed·2026-02-19
CVE-2026-2243 [MEDIUM] CWE-125 GHSA-cw9w-w7fx-35q6: A flaw was found in QEMU
A flaw was found in QEMU. A specially crafted VMDK image could trigger an out-of-bounds read vulnerability, potentially leading to a 12-byte leak of sensitive information or a denial of service condition (DoS).
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-2243 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.1
CVE-2026-2243 [MEDIUM] CVE-2026-2243 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-2243 :
Wolfi vulnerability analysis and mitigation
A flaw was found in QEMU. A specially crafted VMDK image could trigger an out-of-bounds read vulnerability, potentially leading to a 12-byte leak of sensitive information or a denial of service condition (DoS).
Source : NVD
## 5.1
Score
Published February 19, 2026
Severity MEDIUM
CNA Score 5.1
Affected Technologies
Wolfi
Chainguard
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 4.5
Exploitation Probability (EPSS) N/A
Affected packages and libraries
libcacard-tools
qemu-kvm-device-display-virtio-gpu-ccw
Sources
NVD
Chainguard No Fix Added at: Mar 03, 2026
Debian 11, 12, 13 Severity MEDIUM No Fix Added at: Feb 20, 2
Bugzilla
CVE-2026-2243 qemu-kvm: Heap buffer out-of-bounds read in VMDK compressed grain parsing
bugzilla·2026-02-19·CVSS 5.1
CVE-2026-2243 [MEDIUM] CVE-2026-2243 qemu-kvm: Heap buffer out-of-bounds read in VMDK compressed grain parsing
CVE-2026-2243 qemu-kvm: Heap buffer out-of-bounds read in VMDK compressed grain parsing
A heap buffer over-read was found in block/vmdk.c. A crafted VMDK file can make qemu-img (or qemu with vmdk disk) read past an allocated buffer, potentially leading to a 12-byte information leak or denial of service.
Patch:
https://lore.kernel.org/qemu-devel/CAJ9qJssSwxkmEVethg57-Ph6maEfButSaV-r07ma9_x1sp6wYg@mail.gmail.com/
Credit:
Halil Oktay (oblivionsage)
Discussion:
Upstream fix:
https://gitlab.com/qemu-project/qemu/-/commit/cfda94eddb6c9c49b66461c950b22845a46a75c9
2026-02-19
Published