CVE-2026-3195
published 2026-06-19CVE-2026-3195: A flaw was found in QEMU. When reading input audio in the virtio-snd device input callback, the `virtio_snd_pcm_in_cb` function did not check whether the iov…
PriorityP339high7.4CVSS 3.1
AVLACHPRNUINSUCHIHAH
EPSS
0.17%
6.8th percentile
A flaw was found in QEMU. When reading input audio in the virtio-snd device input callback, the `virtio_snd_pcm_in_cb` function did not check whether the iov could fit the data buffer, potentially leading to a heap out-of-bounds write. This issue exists due to an incomplete fix for CVE-2024-7730.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | qemu | < qemu 1:10.2.2+ds-1 (forky) | qemu 1:10.2.2+ds-1 (forky) |
CVSS provenance
nvdv3.17.4HIGHCVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_ubuntu8.2HIGH
vendor_redhat7.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
QEMU virtio_snd_pcm_in_cb heap-based overflow
vuldb·2026-06-19
CVE-2026-3195 [CRITICAL] QEMU virtio_snd_pcm_in_cb heap-based overflow
A vulnerability described as critical has been identified in QEMU. This affects the function virtio_snd_pcm_in_cb. Such manipulation leads to heap-based buffer overflow.
This vulnerability is referenced as CVE-2026-3195. The attack can only be performed from a local environment. No exploit is available.
GHSA
A flaw was found in QEMU.
ghsa_unreviewed·2026-06-19·CVSS 7.8
CVE-2026-3195 [HIGH] CWE-122 A flaw was found in QEMU.
A flaw was found in QEMU. When reading input audio in the virtio-snd device input callback, the `virtio_snd_pcm_in_cb` function did not check whether the iov could fit the data buffer, potentially leading to a heap out-of-bounds write. This issue exists due to an incomplete fix for CVE-2024-7730.
Ubuntu
QEMU vulnerabilities
vendor_ubuntu·2026-04-09·CVSS 8.2
CVE-2024-6519 [HIGH] QEMU vulnerabilities
Title: QEMU vulnerabilities
Summary: Several security issues were fixed in QEMU.
It was discovered that the LSI53C895A SCSI Host Bus Adapter implementation
of QEMU incorrectly handled memory. An attacker inside the guest could
possibly use this issue to cause QEMU to crash, resulting in a denial of
service, or possibly execute arbitrary code. (CVE-2024-6519)
It was discovered that QEMU could be made to read out of bounds when
reading VMDK images. If a user or an automated system were tricked into
opening a specially crafted VMDK image, an attacker could possibly use
this issue to leak sensitive informaton or cause QEMU to crash, resulting
in a denial of service. (CVE-2026-2243)
It was discovered that the virtio-snd device implementation of QEMU could
be made to write out of bounds. An
Red Hat
qemu-kvm: virtio-snd: heap buffer overflow in virtio_snd_pcm_in_cb (incomplete fix for CVE-2024-7730)
vendor_redhat·2026-02-20·CVSS 7.4
CVE-2026-3195 [HIGH] CWE-122 qemu-kvm: virtio-snd: heap buffer overflow in virtio_snd_pcm_in_cb (incomplete fix for CVE-2024-7730)
qemu-kvm: virtio-snd: heap buffer overflow in virtio_snd_pcm_in_cb (incomplete fix for CVE-2024-7730)
A flaw was found in QEMU. When reading input audio in the virtio-snd device input callback, the `virtio_snd_pcm_in_cb` function did not check whether the iov could fit the data buffer, potentially leading to a heap out-of-bounds write. This issue exists due to an incomplete fix for CVE-2024-7730.
Statement: The `qemu-kvm` packages as shipped with Red Hat Enterprise Linux are not affected by this CVE. The virtio-snd device is disabled at build-time in RHEL, effectively removing the attack surface.
Package: qemu-kvm (Red Hat Enterprise Linux 10) - Not affected
Package: qemu-kvm (Red Hat Enterprise Linux 6) - Not affected
Package: qemu-kvm (Red Hat Enterprise Linux 7) - Not affected
Pac
Debian
CVE-2026-3195: qemu
vendor_debian·2026
CVE-2026-3195 [LOW] CVE-2026-3195: qemu
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 1:10.2.2+ds-1)
sid: resolved (fixed in 1:10.2.2+ds-1)
trixie: open
No detection rules found.
No public exploits indexed.
2026-06-19
Published