CVE-2026-3196
published 2026-06-19CVE-2026-3196: An integer overflow vulnerability was found in the virtio-snd device via PCM_INFO requests from the guest. A malicious guest can provide out-of-bounds stream…
PriorityP422medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.10%
1.1th percentile
An integer overflow vulnerability was found in the virtio-snd device via PCM_INFO requests from the guest. A malicious guest can provide out-of-bounds stream counts, potentially leading to unbounded memory allocation on the host and a denial of service condition.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | qemu | < qemu 1:10.2.2+ds-1 (forky) | qemu 1:10.2.2+ds-1 (forky) |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
vendor_ubuntu8.2HIGH
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
An integer overflow vulnerability was found in the virtio-snd device via PCM_INFO requests from the guest.
ghsa_unreviewed·2026-06-19
CVE-2026-3196 [MEDIUM] CWE-190 An integer overflow vulnerability was found in the virtio-snd device via PCM_INFO requests from the guest.
An integer overflow vulnerability was found in the virtio-snd device via PCM_INFO requests from the guest. A malicious guest can provide out-of-bounds stream counts, potentially leading to unbounded memory allocation on the host and a denial of service condition.
VulDB
QEMU integer overflow
vuldb·2026-06-19
CVE-2026-3196 [CRITICAL] QEMU integer overflow
A vulnerability classified as critical has been found in QEMU. This vulnerability affects unknown code. Performing a manipulation results in integer overflow.
This vulnerability is identified as CVE-2026-3196. The attack is only possible with local access. There is not any exploit available.
Ubuntu
QEMU vulnerabilities
vendor_ubuntu·2026-04-09·CVSS 8.2
CVE-2024-6519 [HIGH] QEMU vulnerabilities
Title: QEMU vulnerabilities
Summary: Several security issues were fixed in QEMU.
It was discovered that the LSI53C895A SCSI Host Bus Adapter implementation
of QEMU incorrectly handled memory. An attacker inside the guest could
possibly use this issue to cause QEMU to crash, resulting in a denial of
service, or possibly execute arbitrary code. (CVE-2024-6519)
It was discovered that QEMU could be made to read out of bounds when
reading VMDK images. If a user or an automated system were tricked into
opening a specially crafted VMDK image, an attacker could possibly use
this issue to leak sensitive informaton or cause QEMU to crash, resulting
in a denial of service. (CVE-2026-2243)
It was discovered that the virtio-snd device implementation of QEMU could
be made to write out of bounds. An
Red Hat
qemu-kvm: virtio-snd: integer overflow leading to unbounded memory allocation
vendor_redhat·2026-02-20·CVSS 5.5
CVE-2026-3196 [MEDIUM] CWE-190 qemu-kvm: virtio-snd: integer overflow leading to unbounded memory allocation
qemu-kvm: virtio-snd: integer overflow leading to unbounded memory allocation
An integer overflow vulnerability was found in the virtio-snd device via PCM_INFO requests from the guest. A malicious guest can provide out-of-bounds stream counts, potentially leading to unbounded memory allocation on the host and a denial of service condition.
Statement: The `qemu-kvm` packages as shipped with Red Hat Enterprise Linux are not affected by this CVE. The virtio-snd device is disabled at build-time in RHEL, effectively removing the attack surface.
Package: qemu-kvm (Red Hat Enterprise Linux 10) - Not affected
Package: qemu-kvm (Red Hat Enterprise Linux 6) - Not affected
Package: qemu-kvm (Red Hat Enterprise Linux 7) - Not affected
Package: qemu-kvm-ma (Red Hat Enterprise Linux 7) - Not affec
Debian
CVE-2026-3196: qemu
vendor_debian·2026
CVE-2026-3196 [LOW] CVE-2026-3196: qemu
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 1:10.2.2+ds-1)
sid: resolved (fixed in 1:10.2.2+ds-1)
trixie: open
No detection rules found.
No public exploits indexed.
2026-06-19
Published