cbcvebase.
CVE-2026-2243
published 2026-02-19

CVE-2026-2243: A flaw was found in QEMU. A specially crafted VMDK image could trigger an out-of-bounds read vulnerability, potentially leading to a 12-byte leak of sensitive…

PriorityP419medium5.1CVSS 3.1
AVLACLPRNUINSUCLINAL
EPSS
0.11%
1.7th percentile
A flaw was found in QEMU. A specially crafted VMDK image could trigger an out-of-bounds read vulnerability, potentially leading to a 12-byte leak of sensitive information or a denial of service condition (DoS).

Affected

5 ranges
VendorProductVersion rangeFixed in
debianqemu< qemu 1:10.2.2+ds-1 (forky)qemu 1:10.2.2+ds-1 (forky)
msrcazl3_qemu_8.2.0-27_on_azure_linux_3.0
msrccbl2_qemu_6.2.0-26_on_cbl_mariner_2.0
qemuqemu>= 0 < 1:10.2.2+ds-11:10.2.2+ds-1
ubuntuqemu

CVSS provenance

nvdv3.15.1MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
osv5.1MEDIUM
vendor_ubuntu8.2HIGH
vendor_debian5.1MEDIUM
vendor_msrc5.1MEDIUM
vendor_redhat5.1MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.