Debian Qemu vulnerabilities
424 known vulnerabilities affecting debian/qemu.
Total CVEs
424
CISA KEV
0
Public exploits
7
Exploited in wild
0
Severity breakdown
CRITICAL10HIGH85MEDIUM226LOW102UNKNOWN1
Vulnerabilities
Page 14 of 22
CVE-2025-54567P4LOWCVSS 5.3fixed in qemu 1:10.0.3+ds-1 (forky)2025
CVE-2025-54567 [MEDIUM] CVE-2025-54567: qemu - hw/pci/pcie_sriov.c in QEMU through 10.0.3 mishandles the VF Enable bit write ma...
hw/pci/pcie_sriov.c in QEMU through 10.0.3 mishandles the VF Enable bit write mask, a related issue to CVE-2024-26327.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 1:10.0.3+ds-1)
sid: resolved (fixed in 1:10.0.3+ds-1)
trixie: resolved (fixed in 1:10.0.2+ds-2+deb13u1)
debian
CVE-2025-54566P4LOWCVSS 5.3fixed in qemu 1:10.0.3+ds-1 (forky)2025
CVE-2025-54566 [MEDIUM] CVE-2025-54566: qemu - hw/pci/pcie_sriov.c in QEMU through 10.0.3 has a migration state inconsistency, ...
hw/pci/pcie_sriov.c in QEMU through 10.0.3 has a migration state inconsistency, a related issue to CVE-2024-26327.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 1:10.0.3+ds-1)
sid: resolved (fixed in 1:10.0.3+ds-1)
trixie: resolved (fixed in 1:10.0.2+ds-2+deb13u1)
debian
CVE-2020-29130P4MEDIUMCVSS 4.3fixed in libslirp 4.4.0-1 (bookworm)2020
CVE-2020-29130 [MEDIUM] CVE-2020-29130: libslirp - slirp.c in libslirp through 4.3.1 has a buffer over-read because it tries to rea...
slirp.c in libslirp through 4.3.1 has a buffer over-read because it tries to read a certain amount of header data even if that exceeds the total packet length.
Scope: local
bookworm: resolved (fixed in 4.4.0-1)
bullseye: resolved (fixed in 4.4.0-1)
forky: resolved (fixed in 4.4.0-1)
sid: resolved (fixed in 4.4.0-1)
trixie: resolved (fixed in 4.4.0-1)
debian
CVE-2014-0223P4MEDIUMCVSS 4.6fixed in qemu 2.0.0+dfsg-6 (bookworm)2014
CVE-2014-0223 [MEDIUM] CVE-2014-0223: qemu - Integer overflow in the qcow_open function in block/qcow.c in QEMU before 1.7.2 ...
Integer overflow in the qcow_open function in block/qcow.c in QEMU before 1.7.2 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a large image size, which triggers a buffer overflow or out-of-bounds read.
Scope: local
bookworm: resolved (fixed in 2.0.0+dfsg-6)
bullseye: resolved (fixed in 2.0.0+dfsg-6)
forky: resolved (fix
debian
CVE-2015-8568P4MEDIUMCVSS 6.5fixed in qemu 1:2.5+dfsg-3 (bookworm)2015
CVE-2015-8568 [MEDIUM] CVE-2015-8568: qemu - Memory leak in QEMU, when built with a VMWARE VMXNET3 paravirtual NIC emulator s...
Memory leak in QEMU, when built with a VMWARE VMXNET3 paravirtual NIC emulator support, allows local guest users to cause a denial of service (host memory consumption) by trying to activate the vmxnet3 device repeatedly.
Scope: local
bookworm: resolved (fixed in 1:2.5+dfsg-3)
bullseye: resolved (fixed in 1:2.5+dfsg-3)
forky: resolved (fixed in 1:2.5+dfsg-3)
sid: resolv
debian
CVE-2016-9915P4MEDIUMCVSS 6.5fixed in qemu 1:2.8+dfsg-1 (bookworm)2016
CVE-2016-9915 [MEDIUM] CVE-2016-9915: qemu - Memory leak in hw/9pfs/9p-handle.c in QEMU (aka Quick Emulator) allows local pri...
Memory leak in hw/9pfs/9p-handle.c in QEMU (aka Quick Emulator) allows local privileged guest OS users to cause a denial of service (host memory consumption and possibly QEMU process crash) by leveraging a missing cleanup operation in the handle backend.
Scope: local
bookworm: resolved (fixed in 1:2.8+dfsg-1)
bullseye: resolved (fixed in 1:2.8+dfsg-1)
forky: resolved (
debian
CVE-2016-9914P4MEDIUMCVSS 6.5fixed in qemu 1:2.8+dfsg-1 (bookworm)2016
CVE-2016-9914 [MEDIUM] CVE-2016-9914: qemu - Memory leak in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local privileged...
Memory leak in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local privileged guest OS users to cause a denial of service (host memory consumption and possibly QEMU process crash) by leveraging a missing cleanup operation in FileOperations.
Scope: local
bookworm: resolved (fixed in 1:2.8+dfsg-1)
bullseye: resolved (fixed in 1:2.8+dfsg-1)
forky: resolved (fixed in 1:
debian
CVE-2017-8112P4MEDIUMCVSS 6.5fixed in qemu 1:2.8+dfsg-5 (bookworm)2017
CVE-2017-8112 [MEDIUM] CVE-2017-8112: qemu - hw/scsi/vmw_pvscsi.c in QEMU (aka Quick Emulator) allows local guest OS privileg...
hw/scsi/vmw_pvscsi.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (infinite loop and CPU consumption) via the message ring page count.
Scope: local
bookworm: resolved (fixed in 1:2.8+dfsg-5)
bullseye: resolved (fixed in 1:2.8+dfsg-5)
forky: resolved (fixed in 1:2.8+dfsg-5)
sid: resolved (fixed in 1:2.8+dfsg-5)
trixie:
debian
CVE-2017-5525P4MEDIUMCVSS 6.5fixed in qemu 1:2.8+dfsg-2 (bookworm)2017
CVE-2017-5525 [MEDIUM] CVE-2017-5525: qemu - Memory leak in hw/audio/ac97.c in QEMU (aka Quick Emulator) allows local guest O...
Memory leak in hw/audio/ac97.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption and QEMU process crash) via a large number of device unplug operations.
Scope: local
bookworm: resolved (fixed in 1:2.8+dfsg-2)
bullseye: resolved (fixed in 1:2.8+dfsg-2)
forky: resolved (fixed in 1:2.8+dfsg-2)
sid: re
debian
CVE-2017-5579P4MEDIUMCVSS 6.5fixed in qemu 1:2.8+dfsg-3 (bookworm)2017
CVE-2017-5579 [MEDIUM] CVE-2017-5579: qemu - Memory leak in the serial_exit_core function in hw/char/serial.c in QEMU (aka Qu...
Memory leak in the serial_exit_core function in hw/char/serial.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption and QEMU process crash) via a large number of device unplug operations.
Scope: local
bookworm: resolved (fixed in 1:2.8+dfsg-3)
bullseye: resolved (fixed in 1:2.8+dfsg-3)
forky: resolv
debian
CVE-2017-5526P4MEDIUMCVSS 6.5fixed in qemu 1:2.8+dfsg-2 (bookworm)2017
CVE-2017-5526 [MEDIUM] CVE-2017-5526: qemu - Memory leak in hw/audio/es1370.c in QEMU (aka Quick Emulator) allows local guest...
Memory leak in hw/audio/es1370.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption and QEMU process crash) via a large number of device unplug operations.
Scope: local
bookworm: resolved (fixed in 1:2.8+dfsg-2)
bullseye: resolved (fixed in 1:2.8+dfsg-2)
forky: resolved (fixed in 1:2.8+dfsg-2)
sid:
debian
CVE-2017-12809P4MEDIUMCVSS 6.5fixed in qemu 1:2.10.0-1 (bookworm)2017
CVE-2017-12809 [MEDIUM] CVE-2017-12809: qemu - QEMU (aka Quick Emulator), when built with the IDE disk and CD/DVD-ROM Emulator ...
QEMU (aka Quick Emulator), when built with the IDE disk and CD/DVD-ROM Emulator support, allows local guest OS privileged users to cause a denial of service (NULL pointer dereference and QEMU process crash) by flushing an empty CDROM device drive.
Scope: local
bookworm: resolved (fixed in 1:2.10.0-1)
bullseye: resolved (fixed in 1:2.10.0-1)
forky: resolved (fixed in
debian
CVE-2017-6505P4MEDIUMCVSS 6.5fixed in qemu 1:2.8+dfsg-4 (bookworm)2017
CVE-2017-6505 [MEDIUM] CVE-2017-6505: qemu - The ohci_service_ed_list function in hw/usb/hcd-ohci.c in QEMU (aka Quick Emulat...
The ohci_service_ed_list function in hw/usb/hcd-ohci.c in QEMU (aka Quick Emulator) before 2.9.0 allows local guest OS users to cause a denial of service (infinite loop) via vectors involving the number of link endpoint list descriptors, a different vulnerability than CVE-2017-9330.
Scope: local
bookworm: resolved (fixed in 1:2.8+dfsg-4)
bullseye: resolved (fixed in 1:
debian
CVE-2016-6836P4MEDIUMCVSS 6.0fixed in qemu 1:2.6+dfsg-3.1 (bookworm)2016
CVE-2016-6836 [MEDIUM] CVE-2016-6836: qemu - The vmxnet3_complete_packet function in hw/net/vmxnet3.c in QEMU (aka Quick Emul...
The vmxnet3_complete_packet function in hw/net/vmxnet3.c in QEMU (aka Quick Emulator) allows local guest OS administrators to obtain sensitive host memory information by leveraging failure to initialize the txcq_descr object.
Scope: local
bookworm: resolved (fixed in 1:2.6+dfsg-3.1)
bullseye: resolved (fixed in 1:2.6+dfsg-3.1)
forky: resolved (fixed in 1:2.6+dfsg-3.1)
debian
CVE-2016-7994P4MEDIUMCVSS 6.0fixed in qemu 1:2.8+dfsg-1 (bookworm)2016
CVE-2016-7994 [MEDIUM] CVE-2016-7994: qemu - Memory leak in the virtio_gpu_resource_create_2d function in hw/display/virtio-g...
Memory leak in the virtio_gpu_resource_create_2d function in hw/display/virtio-gpu.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption) via a large number of VIRTIO_GPU_CMD_RESOURCE_CREATE_2D commands.
Scope: local
bookworm: resolved (fixed in 1:2.8+dfsg-1)
bullseye: resolved (fixed in 1:2.8+dfsg-1)
forky
debian
CVE-2016-9103P4MEDIUMCVSS 6.0fixed in qemu 1:2.8+dfsg-1 (bookworm)2016
CVE-2016-9103 [MEDIUM] CVE-2016-9103: qemu - The v9fs_xattrcreate function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allow...
The v9fs_xattrcreate function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to obtain sensitive host heap memory information by reading xattribute values before writing to them.
Scope: local
bookworm: resolved (fixed in 1:2.8+dfsg-1)
bullseye: resolved (fixed in 1:2.8+dfsg-1)
forky: resolved (fixed in 1:2.8+dfsg-1)
sid: resolved (fix
debian
CVE-2024-26328P4MEDIUMCVSS 6.0fixed in qemu 1:7.2+dfsg-7+deb12u6 (bookworm)2024
CVE-2024-26328 [MEDIUM] CVE-2024-26328: qemu - An issue was discovered in QEMU 7.1.0 through 8.2.1. register_vfs in hw/pci/pcie...
An issue was discovered in QEMU 7.1.0 through 8.2.1. register_vfs in hw/pci/pcie_sriov.c does not set NumVFs to PCI_SRIOV_TOTAL_VF, and thus interaction with hw/nvme/ctrl.c is mishandled.
Scope: local
bookworm: resolved (fixed in 1:7.2+dfsg-7+deb12u6)
bullseye: resolved
forky: resolved (fixed in 1:8.2.3+ds-1)
sid: resolved (fixed in 1:8.2.3+ds-1)
trixie: resolved (fi
debian
CVE-2018-7858P4MEDIUMCVSS 5.5fixed in qemu 1:2.12~rc3+dfsg-1 (bookworm)2018
CVE-2018-7858 [MEDIUM] CVE-2018-7858: qemu - Quick Emulator (aka QEMU), when built with the Cirrus CLGD 54xx VGA Emulator sup...
Quick Emulator (aka QEMU), when built with the Cirrus CLGD 54xx VGA Emulator support, allows local guest OS privileged users to cause a denial of service (out-of-bounds access and QEMU process crash) by leveraging incorrect region calculation when updating VGA display.
Scope: local
bookworm: resolved (fixed in 1:2.12~rc3+dfsg-1)
bullseye: resolved (fixed in 1:2.12~rc3+
debian
CVE-2018-18849P4MEDIUMCVSS 5.5fixed in qemu 1:3.1+dfsg-1 (bookworm)2018
CVE-2018-18849 [MEDIUM] CVE-2018-18849: qemu - In Qemu 3.0.0, lsi_do_msgin in hw/scsi/lsi53c895a.c allows out-of-bounds access ...
In Qemu 3.0.0, lsi_do_msgin in hw/scsi/lsi53c895a.c allows out-of-bounds access by triggering an invalid msg_len value.
Scope: local
bookworm: resolved (fixed in 1:3.1+dfsg-1)
bullseye: resolved (fixed in 1:3.1+dfsg-1)
forky: resolved (fixed in 1:3.1+dfsg-1)
sid: resolved (fixed in 1:3.1+dfsg-1)
trixie: resolved (fixed in 1:3.1+dfsg-1)
debian
CVE-2016-5403P4MEDIUMCVSS 5.5fixed in qemu 1:2.6+dfsg-3.1 (bookworm)2016
CVE-2016-5403 [MEDIUM] CVE-2016-5403: qemu - The virtqueue_pop function in hw/virtio/virtio.c in QEMU allows local guest OS a...
The virtqueue_pop function in hw/virtio/virtio.c in QEMU allows local guest OS administrators to cause a denial of service (memory consumption and QEMU process crash) by submitting requests without waiting for completion.
Scope: local
bookworm: resolved (fixed in 1:2.6+dfsg-3.1)
bullseye: resolved (fixed in 1:2.6+dfsg-3.1)
forky: resolved (fixed in 1:2.6+dfsg-3.1)
sid:
debian