CVE-2026-3842
published 2026-07-16CVE-2026-3842: A flaw was found in QEMU. This vulnerability allows a local attacker within a guest virtual machine to write data beyond its allocated memory. This occurs when…
PriorityP343high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.12%
2.0th percentile
A flaw was found in QEMU. This vulnerability allows a local attacker within a guest virtual machine to write data beyond its allocated memory. This occurs when cpu_physical_memory_map() returns a shorter length than expected, leading to an out-of-bounds write. Successful exploitation could result in unauthorized access to guest memory or corruption of heap-allocated objects, potentially causing information disclosure, data integrity issues, or a denial of service.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | qemu | < qemu 1:10.2.2+ds-1 (forky) | qemu 1:10.2.2+ds-1 (forky) |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_ubuntu8.2HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
A flaw was found in QEMU.
ghsa_unreviewed·2026-07-16
CVE-2026-3842 [HIGH] CWE-787 A flaw was found in QEMU.
A flaw was found in QEMU. This vulnerability allows a local attacker within a guest virtual machine to write data beyond its allocated memory. This occurs when cpu_physical_memory_map() returns a shorter length than expected, leading to an out-of-bounds write. Successful exploitation could result in unauthorized access to guest memory or corruption of heap-allocated objects, potentially causing information disclosure, data integrity issues, or a denial of service.
Ubuntu
QEMU vulnerabilities
vendor_ubuntu·2026-04-09·CVSS 8.2
CVE-2024-6519 [HIGH] QEMU vulnerabilities
Title: QEMU vulnerabilities
Summary: Several security issues were fixed in QEMU.
It was discovered that the LSI53C895A SCSI Host Bus Adapter implementation
of QEMU incorrectly handled memory. An attacker inside the guest could
possibly use this issue to cause QEMU to crash, resulting in a denial of
service, or possibly execute arbitrary code. (CVE-2024-6519)
It was discovered that QEMU could be made to read out of bounds when
reading VMDK images. If a user or an automated system were tricked into
opening a specially crafted VMDK image, an attacker could possibly use
this issue to leak sensitive informaton or cause QEMU to crash, resulting
in a denial of service. (CVE-2026-2243)
It was discovered that the virtio-snd device implementation of QEMU could
be made to write out of bounds. An
Red Hat
qemu-kvm: hyperv/syndbg: missing mapped-length guard after cpu_physical_memory_map causes host OOB write
vendor_redhat·2026-03-09·CVSS 7.8
CVE-2026-3842 [HIGH] CWE-787 qemu-kvm: hyperv/syndbg: missing mapped-length guard after cpu_physical_memory_map causes host OOB write
qemu-kvm: hyperv/syndbg: missing mapped-length guard after cpu_physical_memory_map causes host OOB write
A flaw was found in QEMU. This vulnerability allows a local attacker within a guest virtual machine to write data beyond its allocated memory. This occurs when cpu_physical_memory_map() returns a shorter length than expected, leading to an out-of-bounds write. Successful exploitation could result in unauthorized access to guest memory or corruption of heap-allocated objects, potentially causing information disclosure, data integrity issues, or a denial of service.
Statement: The `qemu-kvm` packages as shipped with Red Hat Enterprise Linux are not affected by this CVE. The Hyper-V Synthetic Debugging device (syndbg.c) is disabled at build-time in RHEL, effectively removing the attack s
Debian
CVE-2026-3842: qemu
vendor_debian·2026
CVE-2026-3842 CVE-2026-3842: qemu
bookworm: open
bullseye: resolved
forky: resolved (fixed in 1:10.2.2+ds-1)
sid: resolved (fixed in 1:10.2.2+ds-1)
trixie: open
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-3842 qemu-kvm: hyperv/syndbg: missing mapped-length guard after cpu_physical_memory_map causes host OOB write
bugzilla·2026-04-14
CVE-2026-3842 [HIGH] CVE-2026-3842 qemu-kvm: hyperv/syndbg: missing mapped-length guard after cpu_physical_memory_map causes host OOB write
CVE-2026-3842 qemu-kvm: hyperv/syndbg: missing mapped-length guard after cpu_physical_memory_map causes host OOB write
If cpu_physical_memory_map() returns a length shorter than the one that was passed into the function, writing the full out_len bytes causes an access beyond the memory allocated to the guest; or in the case of the MMIO bounce buffer, an out-of-bounds access in a heap-allocated object.
Upstream fix:
https://gitlab.com/qemu-project/qemu/-/commit/4f28b87fdd24df2049626106b7c24d0180952115
Bugzilla
CVE-2026-3842 qemu: hyperv/syndbg: missing mapped-length guard after cpu_physical_memory_map causes host OOB write [fedora-all]
bugzilla·2026-04-14
CVE-2026-3842 [HIGH] CVE-2026-3842 qemu: hyperv/syndbg: missing mapped-length guard after cpu_physical_memory_map causes host OOB write [fedora-all]
CVE-2026-3842 qemu: hyperv/syndbg: missing mapped-length guard after cpu_physical_memory_map causes host OOB write [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
2026-07-16
Published