Debian Qemu vulnerabilities
424 known vulnerabilities affecting debian/qemu.
Total CVEs
424
CISA KEV
0
Public exploits
7
Exploited in wild
0
Severity breakdown
CRITICAL10HIGH85MEDIUM226LOW102UNKNOWN1
Vulnerabilities
Page 11 of 22
CVE-2019-20808P4MEDIUMCVSS 6.5fixed in qemu 1:4.2-1 (bookworm)2019
CVE-2019-20808 [MEDIUM] CVE-2019-20808: qemu - In QEMU 4.1.0, an out-of-bounds read flaw was found in the ATI VGA implementatio...
In QEMU 4.1.0, an out-of-bounds read flaw was found in the ATI VGA implementation. It occurs in the ati_cursor_define() routine while handling MMIO write operations through the ati_mm_write() callback. A malicious guest could abuse this flaw to crash the QEMU process, resulting in a denial of service.
Scope: local
bookworm: resolved (fixed in 1:4.2-1)
bullseye: resol
debian
CVE-2023-3019P4MEDIUMCVSS 6.0fixed in qemu 1:7.2+dfsg-7+deb12u4 (bookworm)2023
CVE-2023-3019 [MEDIUM] CVE-2023-3019: qemu - A DMA reentrancy issue leading to a use-after-free error was found in the e1000e...
A DMA reentrancy issue leading to a use-after-free error was found in the e1000e NIC emulation code in QEMU. This issue could allow a privileged guest user to crash the QEMU process on the host, resulting in a denial of service.
Scope: local
bookworm: resolved (fixed in 1:7.2+dfsg-7+deb12u4)
bullseye: resolved (fixed in 1:5.2+dfsg-11+deb11u4)
forky: resolved (fixed in
debian
CVE-2016-9846P4MEDIUMCVSS 6.5fixed in qemu 1:2.8+dfsg-1 (bookworm)2016
CVE-2016-9846 [MEDIUM] CVE-2016-9846: qemu - QEMU (aka Quick Emulator) built with the Virtio GPU Device emulator support is v...
QEMU (aka Quick Emulator) built with the Virtio GPU Device emulator support is vulnerable to a memory leakage issue. It could occur while updating the cursor data in update_cursor_data_virgl. A guest user/process could use this flaw to leak host memory bytes, resulting in DoS for a host.
Scope: local
bookworm: resolved (fixed in 1:2.8+dfsg-1)
bullseye: resolved (fixed
debian
CVE-2015-8701P4MEDIUMCVSS 6.5fixed in qemu 1:2.5+dfsg-3 (bookworm)2015
CVE-2015-8701 [MEDIUM] CVE-2015-8701: qemu - QEMU (aka Quick Emulator) built with the Rocker switch emulation support is vuln...
QEMU (aka Quick Emulator) built with the Rocker switch emulation support is vulnerable to an off-by-one error. It happens while processing transmit (tx) descriptors in 'tx_consume' routine, if a descriptor was to have more than allowed (ROCKER_TX_FRAGS_MAX=16) fragments. A privileged user inside guest could use this flaw to cause memory leakage on the host or crash the
debian
CVE-2016-9911P4MEDIUMCVSS 6.5fixed in qemu 1:2.8+dfsg-1 (bookworm)2016
CVE-2016-9911 [MEDIUM] CVE-2016-9911: qemu - Quick Emulator (Qemu) built with the USB EHCI Emulation support is vulnerable to...
Quick Emulator (Qemu) built with the USB EHCI Emulation support is vulnerable to a memory leakage issue. It could occur while processing packet data in 'ehci_init_transfer'. A guest user/process could use this issue to leak host memory, resulting in DoS for a host.
Scope: local
bookworm: resolved (fixed in 1:2.8+dfsg-1)
bullseye: resolved (fixed in 1:2.8+dfsg-1)
forky:
debian
CVE-2020-27661P4MEDIUMCVSS 6.5fixed in qemu 1:5.2+dfsg-1 (bookworm)2020
CVE-2020-27661 [MEDIUM] CVE-2020-27661: qemu - A divide-by-zero issue was found in dwc2_handle_packet in hw/usb/hcd-dwc2.c in t...
A divide-by-zero issue was found in dwc2_handle_packet in hw/usb/hcd-dwc2.c in the hcd-dwc2 USB host controller emulation of QEMU. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service.
Scope: local
bookworm: resolved (fixed in 1:5.2+dfsg-1)
bullseye: resolved (fixed in 1:5.2+dfsg-1)
forky: resolved (fixed in 1:
debian
CVE-2022-4144P4MEDIUMCVSS 6.5fixed in qemu 1:7.2+dfsg-1 (bookworm)2022
CVE-2022-4144 [MEDIUM] CVE-2022-4144: qemu - An out-of-bounds read flaw was found in the QXL display device emulation in QEMU...
An out-of-bounds read flaw was found in the QXL display device emulation in QEMU. The qxl_phys2virt() function does not check the size of the structure pointed to by the guest physical address, potentially reading past the end of the bar space into adjacent pages. A malicious guest user could use this flaw to crash the QEMU process on the host causing a denial of servi
debian
CVE-2021-3409P4MEDIUMCVSS 6.3fixed in qemu 1:5.2+dfsg-10 (bookworm)2021
CVE-2021-3409 [MEDIUM] CVE-2021-3409: qemu - The patch for CVE-2020-17380/CVE-2020-25085 was found to be ineffective, thus ma...
The patch for CVE-2020-17380/CVE-2020-25085 was found to be ineffective, thus making QEMU vulnerable to the out-of-bounds read/write access issues previously found in the SDHCI controller emulation code. This flaw allows a malicious privileged guest to crash the QEMU process on the host, resulting in a denial of service or potential code execution. QEMU up to (includin
debian
CVE-2020-27821P4MEDIUMCVSS 6.0fixed in qemu 1:5.2+dfsg-3 (bookworm)2020
CVE-2020-27821 [MEDIUM] CVE-2020-27821: qemu - A flaw was found in the memory management API of QEMU during the initialization ...
A flaw was found in the memory management API of QEMU during the initialization of a memory region cache. This issue could lead to an out-of-bounds write access to the MSI-X table while performing MMIO operations. A guest user may abuse this flaw to crash the QEMU process on the host, resulting in a denial of service. This flaw affects QEMU versions prior to 5.2.0.
S
debian
CVE-2021-3607P4MEDIUMCVSS 6.0fixed in qemu 1:5.2+dfsg-11 (bookworm)2021
CVE-2021-3607 [MEDIUM] CVE-2021-3607: qemu - An integer overflow was found in the QEMU implementation of VMWare's paravirtual...
An integer overflow was found in the QEMU implementation of VMWare's paravirtual RDMA device in versions prior to 6.1.0. The issue occurs while handling a "PVRDMA_REG_DSRHIGH" write from the guest due to improper input validation. This flaw allows a privileged guest user to make QEMU allocate a large amount of memory, resulting in a denial of service. The highest threa
debian
CVE-2021-20255P4MEDIUMCVSS 5.5fixed in qemu 1:8.1.0+ds-1 (forky)2021
CVE-2021-20255 [MEDIUM] CVE-2021-20255: qemu - A stack overflow via an infinite recursion vulnerability was found in the eepro1...
A stack overflow via an infinite recursion vulnerability was found in the eepro100 i8255x device emulator of QEMU. This issue occurs while processing controller commands due to a DMA reentry issue. This flaw allows a guest user or process to consume CPU cycles or crash the QEMU process on the host, resulting in a denial of service. The highest threat from this vulner
debian
CVE-2020-10702P4MEDIUMCVSS 5.5fixed in qemu 1:4.2-5 (bookworm)2020
CVE-2020-10702 [MEDIUM] CVE-2020-10702: qemu - A flaw was found in QEMU in the implementation of the Pointer Authentication (PA...
A flaw was found in QEMU in the implementation of the Pointer Authentication (PAuth) support for ARM introduced in version 4.0 and fixed in version 5.0.0. A general failure of the signature generation process caused every PAuth-enforced pointer to be signed with the same signature. A local attacker could obtain the signature of a protected pointer and abuse this flaw
debian
CVE-2025-14876P4MEDIUMCVSS 5.5fixed in qemu 1:10.2.1+ds-1 (forky)2025
CVE-2025-14876 [MEDIUM] CVE-2025-14876: qemu - A flaw was found in the virtio-crypto device of QEMU. A malicious guest operatin...
A flaw was found in the virtio-crypto device of QEMU. A malicious guest operating system can exploit a missing length limit in the AKCIPHER path, leading to uncontrolled memory allocation. This can result in a denial of service (DoS) on the host system by causing the QEMU process to terminate unexpectedly.
Scope: local
bookworm: open
bullseye: resolved
forky: resolve
debian
CVE-2023-0330P4MEDIUMCVSS 5.3fixed in qemu 1:7.2+dfsg-7+deb12u1 (bookworm)2023
CVE-2023-0330 [MEDIUM] CVE-2023-0330: qemu - A vulnerability in the lsi53c895a device affects the latest version of qemu. A D...
A vulnerability in the lsi53c895a device affects the latest version of qemu. A DMA-MMIO reentrancy problem may lead to memory corruption bugs like stack overflow or use-after-free.
Scope: local
bookworm: resolved (fixed in 1:7.2+dfsg-7+deb12u1)
bullseye: resolved (fixed in 1:5.2+dfsg-11+deb11u3)
forky: resolved (fixed in 1:8.0.2+dfsg-1)
sid: resolved (fixed in 1:8.0.2+
debian
CVE-2014-8106P4HIGHCVSS 7.2fixed in qemu 2.1+dfsg-9 (bookworm)2014
CVE-2014-8106 [HIGH] CVE-2014-8106: qemu - Heap-based buffer overflow in the Cirrus VGA emulator (hw/display/cirrus_vga.c) ...
Heap-based buffer overflow in the Cirrus VGA emulator (hw/display/cirrus_vga.c) in QEMU before 2.2.0 allows local guest users to execute arbitrary code via vectors related to blit regions. NOTE: this vulnerability exists because an incomplete fix for CVE-2007-1320.
Scope: local
bookworm: resolved (fixed in 2.1+dfsg-9)
bullseye: resolved (fixed in 2.1+dfsg-9)
forky: resol
debian
CVE-2008-0928P4LOWCVSS 4.7fixed in qemu 0.9.1+svn20081207-1 (bookworm)2008
CVE-2008-0928 [MEDIUM] CVE-2008-0928: qemu - Qemu 0.9.1 and earlier does not perform range checks for block device read or wr...
Qemu 0.9.1 and earlier does not perform range checks for block device read or write requests, which allows guest host users with root privileges to access arbitrary memory and escape the virtual machine.
Scope: local
bookworm: resolved (fixed in 0.9.1+svn20081207-1)
bullseye: resolved (fixed in 0.9.1+svn20081207-1)
forky: resolved (fixed in 0.9.1+svn20081207-1)
sid: re
debian
CVE-2016-9907P4MEDIUMCVSS 6.5fixed in qemu 1:2.8+dfsg-1 (bookworm)2016
CVE-2016-9907 [MEDIUM] CVE-2016-9907: qemu - Quick Emulator (Qemu) built with the USB redirector usb-guest support is vulnera...
Quick Emulator (Qemu) built with the USB redirector usb-guest support is vulnerable to a memory leakage flaw. It could occur while destroying the USB redirector in 'usbredir_handle_destroy'. A guest user/process could use this issue to leak host memory, resulting in DoS for a host.
Scope: local
bookworm: resolved (fixed in 1:2.8+dfsg-1)
bullseye: resolved (fixed in 1:2
debian
CVE-2016-9912P4MEDIUMCVSS 6.5fixed in qemu 1:2.8+dfsg-1 (bookworm)2016
CVE-2016-9912 [MEDIUM] CVE-2016-9912: qemu - Quick Emulator (Qemu) built with the Virtio GPU Device emulator support is vulne...
Quick Emulator (Qemu) built with the Virtio GPU Device emulator support is vulnerable to a memory leakage issue. It could occur while destroying gpu resource object in 'virtio_gpu_resource_destroy'. A guest user/process could use this flaw to leak host memory bytes, resulting in DoS for a host.
Scope: local
bookworm: resolved (fixed in 1:2.8+dfsg-1)
bullseye: resolved
debian
CVE-2017-5552P4LOWCVSS 6.5fixed in qemu 1:2.10.0-1 (bookworm)2017
CVE-2017-5552 [MEDIUM] CVE-2017-5552: qemu - Memory leak in the virgl_resource_attach_backing function in hw/display/virtio-g...
Memory leak in the virgl_resource_attach_backing function in hw/display/virtio-gpu-3d.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a denial of service (host memory consumption) via a large number of VIRTIO_GPU_CMD_RESOURCE_ATTACH_BACKING commands.
Scope: local
bookworm: resolved (fixed in 1:2.10.0-1)
bullseye: resolved (fixed in 1:2.10.0-1)
forky
debian
CVE-2017-5578P4LOWCVSS 6.5fixed in qemu 1:2.10.0-1 (bookworm)2017
CVE-2017-5578 [MEDIUM] CVE-2017-5578: qemu - Memory leak in the virtio_gpu_resource_attach_backing function in hw/display/vir...
Memory leak in the virtio_gpu_resource_attach_backing function in hw/display/virtio-gpu.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a denial of service (host memory consumption) via a large number of VIRTIO_GPU_CMD_RESOURCE_ATTACH_BACKING commands.
Scope: local
bookworm: resolved (fixed in 1:2.10.0-1)
bullseye: resolved (fixed in 1:2.10.0-1)
for
debian