Debian Qemu vulnerabilities
424 known vulnerabilities affecting debian/qemu.
Total CVEs
424
CISA KEV
0
Public exploits
7
Exploited in wild
0
Severity breakdown
CRITICAL10HIGH85MEDIUM226LOW102UNKNOWN1
Vulnerabilities
Page 13 of 22
CVE-2016-9916P4MEDIUMCVSS 6.5fixed in qemu 1:2.8+dfsg-1 (bookworm)2016
CVE-2016-9916 [MEDIUM] CVE-2016-9916: qemu - Memory leak in hw/9pfs/9p-proxy.c in QEMU (aka Quick Emulator) allows local priv...
Memory leak in hw/9pfs/9p-proxy.c in QEMU (aka Quick Emulator) allows local privileged guest OS users to cause a denial of service (host memory consumption and possibly QEMU process crash) by leveraging a missing cleanup operation in the proxy backend.
Scope: local
bookworm: resolved (fixed in 1:2.8+dfsg-1)
bullseye: resolved (fixed in 1:2.8+dfsg-1)
forky: resolved (fi
debian
CVE-2017-8086P4MEDIUMCVSS 6.5fixed in qemu 1:2.8+dfsg-5 (bookworm)2017
CVE-2017-8086 [MEDIUM] CVE-2017-8086: qemu - Memory leak in the v9fs_list_xattr function in hw/9pfs/9p-xattr.c in QEMU (aka Q...
Memory leak in the v9fs_list_xattr function in hw/9pfs/9p-xattr.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (memory consumption) via vectors involving the orig_value variable.
Scope: local
bookworm: resolved (fixed in 1:2.8+dfsg-5)
bullseye: resolved (fixed in 1:2.8+dfsg-5)
forky: resolved (fixed in 1:2.8+dfsg-5)
s
debian
CVE-2017-8379P4MEDIUMCVSS 6.5fixed in qemu 1:2.8+dfsg-5 (bookworm)2017
CVE-2017-8379 [MEDIUM] CVE-2017-8379: qemu - Memory leak in the keyboard input event handlers support in QEMU (aka Quick Emul...
Memory leak in the keyboard input event handlers support in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption) by rapidly generating large keyboard events.
Scope: local
bookworm: resolved (fixed in 1:2.8+dfsg-5)
bullseye: resolved (fixed in 1:2.8+dfsg-5)
forky: resolved (fixed in 1:2.8+dfsg-5)
sid: re
debian
CVE-2016-9913P4MEDIUMCVSS 6.5fixed in qemu 1:2.8+dfsg-1 (bookworm)2016
CVE-2016-9913 [MEDIUM] CVE-2016-9913: qemu - Memory leak in the v9fs_device_unrealize_common function in hw/9pfs/9p.c in QEMU...
Memory leak in the v9fs_device_unrealize_common function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local privileged guest OS users to cause a denial of service (host memory consumption and possibly QEMU process crash) via vectors involving the order of resource cleanup.
Scope: local
bookworm: resolved (fixed in 1:2.8+dfsg-1)
bullseye: resolved (fixed in 1:2.8
debian
CVE-2016-2392P4MEDIUMCVSS 6.5fixed in qemu 1:2.6+dfsg-1 (bookworm)2016
CVE-2016-2392 [MEDIUM] CVE-2016-2392: qemu - The is_rndis function in the USB Net device emulator (hw/usb/dev-network.c) in Q...
The is_rndis function in the USB Net device emulator (hw/usb/dev-network.c) in QEMU before 2.5.1 does not properly validate USB configuration descriptor objects, which allows local guest OS administrators to cause a denial of service (NULL pointer dereference and QEMU process crash) via vectors involving a remote NDIS control message packet.
Scope: local
bookworm: reso
debian
CVE-2020-13800P4MEDIUMCVSS 6.0fixed in qemu 1:5.0-6 (bookworm)2020
CVE-2020-13800 [MEDIUM] CVE-2020-13800: qemu - ati-vga in hw/display/ati.c in QEMU 4.2.0 allows guest OS users to trigger infin...
ati-vga in hw/display/ati.c in QEMU 4.2.0 allows guest OS users to trigger infinite recursion via a crafted mm_index value during an ati_mm_read or ati_mm_write call.
Scope: local
bookworm: resolved (fixed in 1:5.0-6)
bullseye: resolved (fixed in 1:5.0-6)
forky: resolved (fixed in 1:5.0-6)
sid: resolved (fixed in 1:5.0-6)
trixie: resolved (fixed in 1:5.0-6)
debian
CVE-2016-4441P4MEDIUMCVSS 6.0fixed in qemu 1:2.6+dfsg-2 (bookworm)2016
CVE-2016-4441 [MEDIUM] CVE-2016-4441: qemu - The get_cmd function in hw/scsi/esp.c in the 53C9X Fast SCSI Controller (FSC) su...
The get_cmd function in hw/scsi/esp.c in the 53C9X Fast SCSI Controller (FSC) support in QEMU does not properly check DMA length, which allows local guest OS administrators to cause a denial of service (out-of-bounds write and QEMU process crash) via unspecified vectors, involving an SCSI command.
Scope: local
bookworm: resolved (fixed in 1:2.6+dfsg-2)
bullseye: resolv
debian
CVE-2021-20221P4MEDIUMCVSS 6.0fixed in qemu 1:5.2+dfsg-4 (bookworm)2021
CVE-2021-20221 [MEDIUM] CVE-2021-20221: qemu - An out-of-bounds heap buffer access issue was found in the ARM Generic Interrupt...
An out-of-bounds heap buffer access issue was found in the ARM Generic Interrupt Controller emulator of QEMU up to and including qemu 4.2.0on aarch64 platform. The issue occurs because while writing an interrupt ID to the controller memory area, it is not masked to be 4 bits wide. It may lead to the said issue while updating controller state fields and their subseque
debian
CVE-2023-1544P4MEDIUMCVSS 6.0fixed in qemu 1:7.2+dfsg-7+deb12u3 (bookworm)2023
CVE-2023-1544 [MEDIUM] CVE-2023-1544: qemu - A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device....
A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device. This flaw allows a crafted guest driver to allocate and initialize a huge number of page tables to be used as a ring of descriptors for CQ and async events, potentially leading to an out-of-bounds read and crash of QEMU.
Scope: local
bookworm: resolved (fixed in 1:7.2+dfsg-7+deb12u3)
bulls
debian
CVE-2018-19665P4LOWCVSS 5.7fixed in qemu 1:3.1+dfsg-2 (bookworm)2018
CVE-2018-19665 [MEDIUM] CVE-2018-19665: qemu - The Bluetooth subsystem in QEMU mishandles negative values for length variables,...
The Bluetooth subsystem in QEMU mishandles negative values for length variables, leading to memory corruption.
Scope: local
bookworm: resolved (fixed in 1:3.1+dfsg-2)
bullseye: resolved (fixed in 1:3.1+dfsg-2)
forky: resolved (fixed in 1:3.1+dfsg-2)
sid: resolved (fixed in 1:3.1+dfsg-2)
trixie: resolved (fixed in 1:3.1+dfsg-2)
debian
CVE-2016-9923P4MEDIUMCVSS 5.5fixed in qemu 1:2.8+dfsg-1 (bookworm)2016
CVE-2016-9923 [MEDIUM] CVE-2016-9923: qemu - Quick Emulator (Qemu) built with the 'chardev' backend support is vulnerable to ...
Quick Emulator (Qemu) built with the 'chardev' backend support is vulnerable to a use after free issue. It could occur while hotplug and unplugging the device in the guest. A guest user/process could use this flaw to crash a Qemu process on the host resulting in DoS.
Scope: local
bookworm: resolved (fixed in 1:2.8+dfsg-1)
bullseye: resolved (fixed in 1:2.8+dfsg-1)
fork
debian
CVE-2018-18954P4LOWCVSS 5.5fixed in qemu 1:3.1+dfsg-1 (bookworm)2018
CVE-2018-18954 [MEDIUM] CVE-2018-18954: qemu - The pnv_lpc_do_eccb function in hw/ppc/pnv_lpc.c in Qemu before 3.1 allows out-o...
The pnv_lpc_do_eccb function in hw/ppc/pnv_lpc.c in Qemu before 3.1 allows out-of-bounds write or read access to PowerNV memory.
Scope: local
bookworm: resolved (fixed in 1:3.1+dfsg-1)
bullseye: resolved (fixed in 1:3.1+dfsg-1)
forky: resolved (fixed in 1:3.1+dfsg-1)
sid: resolved (fixed in 1:3.1+dfsg-1)
trixie: resolved (fixed in 1:3.1+dfsg-1)
debian
CVE-2023-3301P4MEDIUMCVSS 5.6fixed in qemu 1:7.2+dfsg-7+deb12u1 (bookworm)2023
CVE-2023-3301 [MEDIUM] CVE-2023-3301: qemu - A flaw was found in QEMU. The async nature of hot-unplug enables a race scenario...
A flaw was found in QEMU. The async nature of hot-unplug enables a race scenario where the net device backend is cleared before the virtio-net pci frontend has been unplugged. A malicious guest could use this time window to trigger an assertion and cause a denial of service.
Scope: local
bookworm: resolved (fixed in 1:7.2+dfsg-7+deb12u1)
bullseye: resolved (fixed in 1:
debian
CVE-2018-20124P4LOWCVSS 5.5fixed in qemu 1:4.1-1 (bookworm)2018
CVE-2018-20124 [MEDIUM] CVE-2018-20124: qemu - hw/rdma/rdma_backend.c in QEMU allows guest OS users to trigger out-of-bounds ac...
hw/rdma/rdma_backend.c in QEMU allows guest OS users to trigger out-of-bounds access via a PvrdmaSqWqe ring element with a large num_sge value.
Scope: local
bookworm: resolved (fixed in 1:4.1-1)
bullseye: resolved (fixed in 1:4.1-1)
forky: resolved (fixed in 1:4.1-1)
sid: resolved (fixed in 1:4.1-1)
trixie: resolved (fixed in 1:4.1-1)
debian
CVE-2017-10806P4MEDIUMCVSS 5.5fixed in qemu 1:2.8+dfsg-7 (bookworm)2017
CVE-2017-10806 [MEDIUM] CVE-2017-10806: qemu - Stack-based buffer overflow in hw/usb/redirect.c in QEMU (aka Quick Emulator) al...
Stack-based buffer overflow in hw/usb/redirect.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a denial of service (QEMU process crash) via vectors related to logging debug messages.
Scope: local
bookworm: resolved (fixed in 1:2.8+dfsg-7)
bullseye: resolved (fixed in 1:2.8+dfsg-7)
forky: resolved (fixed in 1:2.8+dfsg-7)
sid: resolved (fixed in 1:2
debian
CVE-2016-5337P4MEDIUMCVSS 5.5fixed in qemu 1:2.6+dfsg-2 (bookworm)2016
CVE-2016-5337 [MEDIUM] CVE-2016-5337: qemu - The megasas_ctrl_get_info function in hw/scsi/megasas.c in QEMU allows local gue...
The megasas_ctrl_get_info function in hw/scsi/megasas.c in QEMU allows local guest OS administrators to obtain sensitive host memory information via vectors related to reading device control information.
Scope: local
bookworm: resolved (fixed in 1:2.6+dfsg-2)
bullseye: resolved (fixed in 1:2.6+dfsg-2)
forky: resolved (fixed in 1:2.6+dfsg-2)
sid: resolved (fixed in 1:2.
debian
CVE-2024-4693P4LOWCVSS 5.5fixed in qemu 1:8.2.3+ds-1 (forky)2024
CVE-2024-4693 [MEDIUM] CVE-2024-4693: qemu - A flaw was found in the QEMU Virtio PCI Bindings (hw/virtio/virtio-pci.c). An im...
A flaw was found in the QEMU Virtio PCI Bindings (hw/virtio/virtio-pci.c). An improper release and use of the irqfd for vector 0 during the boot process leads to a guest triggerable crash via vhost_net_stop(). This flaw allows a malicious guest to crash the QEMU process on the host.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 1:8.2.3+ds
debian
CVE-2014-0148P4MEDIUMCVSS 5.5fixed in qemu 2.0.0+dfsg-1 (bookworm)2014
CVE-2014-0148 [MEDIUM] CVE-2014-0148: qemu - Qemu before 2.0 block driver for Hyper-V VHDX Images is vulnerable to infinite l...
Qemu before 2.0 block driver for Hyper-V VHDX Images is vulnerable to infinite loops and other potential issues when calculating BAT entries, due to missing bounds checks for block_size and logical_sector_size variables. These are used to derive other fields like 'sectors_per_block' etc. A user able to alter the Qemu disk image could ise this flaw to crash the Qemu ins
debian
CVE-2024-8354P4MEDIUMCVSS 5.5fixed in qemu 1:10.1.1+ds-1 (forky)2024
CVE-2024-8354 [MEDIUM] CVE-2024-8354: qemu - A flaw was found in QEMU. An assertion failure was present in the usb_ep_get() f...
A flaw was found in QEMU. An assertion failure was present in the usb_ep_get() function in hw/net/core.c when trying to get the USB endpoint from a USB device. This flaw may allow a malicious unprivileged guest user to crash the QEMU process on the host and cause a denial of service condition.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1:10.1.
debian
CVE-2024-26327P4MEDIUMCVSS 5.3fixed in qemu 1:7.2+dfsg-7+deb12u6 (bookworm)2024
CVE-2024-26327 [MEDIUM] CVE-2024-26327: qemu - An issue was discovered in QEMU 7.1.0 through 8.2.1. register_vfs in hw/pci/pcie...
An issue was discovered in QEMU 7.1.0 through 8.2.1. register_vfs in hw/pci/pcie_sriov.c mishandles the situation where a guest writes NumVFs greater than TotalVFs, leading to a buffer overflow in VF implementations.
Scope: local
bookworm: resolved (fixed in 1:7.2+dfsg-7+deb12u6)
bullseye: resolved
forky: resolved (fixed in 1:8.2.3+ds-1)
sid: resolved (fixed in 1:8.2
debian