cbcvebase.

Debian Qemu vulnerabilities

424 known vulnerabilities affecting debian/qemu.

Total CVEs
424
CISA KEV
0
Public exploits
7
Exploited in wild
0
Severity breakdown
CRITICAL10HIGH85MEDIUM226LOW102UNKNOWN1

Vulnerabilities

Page 15 of 22
CVE-2018-20126P4LOWCVSS 5.5fixed in qemu 1:4.1-1 (bookworm)2018
CVE-2018-20126 [MEDIUM] CVE-2018-20126: qemu - hw/rdma/vmw/pvrdma_cmd.c in QEMU allows create_cq and create_qp memory leaks bec... hw/rdma/vmw/pvrdma_cmd.c in QEMU allows create_cq and create_qp memory leaks because errors are mishandled. Scope: local bookworm: resolved (fixed in 1:4.1-1) bullseye: resolved (fixed in 1:4.1-1) forky: resolved (fixed in 1:4.1-1) sid: resolved (fixed in 1:4.1-1) trixie: resolved (fixed in 1:4.1-1)
debian
CVE-2024-3567P4LOWCVSS 5.5fixed in qemu 1:8.2.3+ds-1 (forky)2024
CVE-2024-3567 [MEDIUM] CVE-2024-3567: qemu - A flaw was found in QEMU. An assertion failure was present in the update_sctp_ch... A flaw was found in QEMU. An assertion failure was present in the update_sctp_checksum() function in hw/net/net_tx_pkt.c when trying to calculate the checksum of a short-sized fragmented packet. This flaw allows a malicious guest to crash QEMU and cause a denial of service condition. Scope: local bookworm: resolved bullseye: resolved forky: resolved (fixed in 1:8.2.3+d
debian
CVE-2016-1981P4MEDIUMCVSS 5.5fixed in qemu 1:2.5+dfsg-5 (bookworm)2016
CVE-2016-1981 [MEDIUM] CVE-2016-1981: qemu - QEMU (aka Quick Emulator) built with the e1000 NIC emulation support is vulnerab... QEMU (aka Quick Emulator) built with the e1000 NIC emulation support is vulnerable to an infinite loop issue. It could occur while processing data via transmit or receive descriptors, provided the initial receive/transmit descriptor head (TDH/RDH) is set outside the allocated descriptor buffer. A privileged user inside guest could use this flaw to crash the QEMU instan
debian
CVE-2016-1922P4MEDIUMCVSS 5.5fixed in qemu 1:2.5+dfsg-4 (bookworm)2016
CVE-2016-1922 [MEDIUM] CVE-2016-1922: qemu - QEMU (aka Quick Emulator) built with the TPR optimization for 32-bit Windows gue... QEMU (aka Quick Emulator) built with the TPR optimization for 32-bit Windows guests support is vulnerable to a null pointer dereference flaw. It occurs while doing I/O port write operations via hmp interface. In that, 'current_cpu' remains null, which leads to the null pointer dereference. A user or process could use this flaw to crash the QEMU instance, resulting in D
debian
CVE-2016-10028P4LOWCVSS 5.5fixed in qemu 1:2.10.0-1 (bookworm)2016
CVE-2016-10028 [MEDIUM] CVE-2016-10028: qemu - The virgl_cmd_get_capset function in hw/display/virtio-gpu-3d.c in QEMU (aka Qui... The virgl_cmd_get_capset function in hw/display/virtio-gpu-3d.c in QEMU (aka Quick Emulator) built with Virtio GPU Device emulator support allows local guest OS users to cause a denial of service (out-of-bounds read and process crash) via a VIRTIO_GPU_CMD_GET_CAPSET command with a maximum capabilities size with a value of 0. Scope: local bookworm: resolved (fixed in
debian
CVE-2020-13253P4MEDIUMCVSS 5.5fixed in qemu 1:5.0-8 (bookworm)2020
CVE-2020-13253 [MEDIUM] CVE-2020-13253: qemu - sd_wp_addr in hw/sd/sd.c in QEMU 4.2.0 uses an unvalidated address, which leads ... sd_wp_addr in hw/sd/sd.c in QEMU 4.2.0 uses an unvalidated address, which leads to an out-of-bounds read during sdhci_write() operations. A guest OS user can crash the QEMU process. Scope: local bookworm: resolved (fixed in 1:5.0-8) bullseye: resolved (fixed in 1:5.0-8) forky: resolved (fixed in 1:5.0-8) sid: resolved (fixed in 1:5.0-8) trixie: resolved (fixed in 1:5
debian
CVE-2016-9776P4MEDIUMCVSS 5.5fixed in qemu 1:2.8+dfsg-1 (bookworm)2016
CVE-2016-9776 [MEDIUM] CVE-2016-9776: qemu - QEMU (aka Quick Emulator) built with the ColdFire Fast Ethernet Controller emula... QEMU (aka Quick Emulator) built with the ColdFire Fast Ethernet Controller emulator support is vulnerable to an infinite loop issue. It could occur while receiving packets in 'mcf_fec_receive'. A privileged user/process inside guest could use this issue to crash the QEMU process on the host leading to DoS. Scope: local bookworm: resolved (fixed in 1:2.8+dfsg-1) bullsey
debian
CVE-2023-42467P4MEDIUMCVSS 5.5fixed in qemu 1:7.2+dfsg-7+deb12u3 (bookworm)2023
CVE-2023-42467 [MEDIUM] CVE-2023-42467: qemu - QEMU through 8.0.0 could trigger a division by zero in scsi_disk_reset in hw/scs... QEMU through 8.0.0 could trigger a division by zero in scsi_disk_reset in hw/scsi/scsi-disk.c because scsi_disk_emulate_mode_select does not prevent s->qdev.blocksize from being 256. This stops QEMU and the guest immediately. Scope: local bookworm: resolved (fixed in 1:7.2+dfsg-7+deb12u3) bullseye: resolved forky: resolved (fixed in 1:8.1.1+ds-1) sid: resolved (fixed
debian
CVE-2020-25624P4MEDIUMCVSS 5.0fixed in qemu 1:5.2+dfsg-1 (bookworm)2020
CVE-2020-25624 [MEDIUM] CVE-2020-25624: qemu - hw/usb/hcd-ohci.c in QEMU 5.0.0 has a stack-based buffer over-read via values ob... hw/usb/hcd-ohci.c in QEMU 5.0.0 has a stack-based buffer over-read via values obtained from the host controller driver. Scope: local bookworm: resolved (fixed in 1:5.2+dfsg-1) bullseye: resolved (fixed in 1:5.2+dfsg-1) forky: resolved (fixed in 1:5.2+dfsg-1) sid: resolved (fixed in 1:5.2+dfsg-1) trixie: resolved (fixed in 1:5.2+dfsg-1)
debian
CVE-2013-4544P4MEDIUMCVSS 4.9fixed in qemu 2.0.0+dfsg-1 (bookworm)2013
CVE-2013-4544 [MEDIUM] CVE-2013-4544: qemu - hw/net/vmxnet3.c in QEMU 2.0.0-rc0, 1.7.1, and earlier allows local guest users ... hw/net/vmxnet3.c in QEMU 2.0.0-rc0, 1.7.1, and earlier allows local guest users to cause a denial of service or possibly execute arbitrary code via vectors related to (1) RX or (2) TX queue numbers or (3) interrupt indices. NOTE: some of these details are obtained from third party information. Scope: local bookworm: resolved (fixed in 2.0.0+dfsg-1) bullseye: resolved (
debian
CVE-2020-29129P4MEDIUMCVSS 4.3fixed in libslirp 4.4.0-1 (bookworm)2020
CVE-2020-29129 [MEDIUM] CVE-2020-29129: libslirp - ncsi.c in libslirp through 4.3.1 has a buffer over-read because it tries to read... ncsi.c in libslirp through 4.3.1 has a buffer over-read because it tries to read a certain amount of header data even if that exceeds the total packet length. Scope: local bookworm: resolved (fixed in 4.4.0-1) bullseye: resolved (fixed in 4.4.0-1) forky: resolved (fixed in 4.4.0-1) sid: resolved (fixed in 4.4.0-1) trixie: resolved (fixed in 4.4.0-1)
debian
CVE-2026-3196P4LOWfixed in qemu 1:10.2.2+ds-1 (forky)2026
CVE-2026-3196 [LOW] CVE-2026-3196: qemu bookworm: resolved bullseye: resolved forky: resolved (fixed in 1:10.2.2+ds-1) sid: resolved (fixed in 1:10.2.2+ds-1) trixie: open
debian
CVE-2017-17381P4MEDIUMCVSS 6.5fixed in qemu 1:2.11+dfsg-1 (bookworm)2017
CVE-2017-17381 [MEDIUM] CVE-2017-17381: qemu - The Virtio Vring implementation in QEMU allows local OS guest users to cause a d... The Virtio Vring implementation in QEMU allows local OS guest users to cause a denial of service (divide-by-zero error and QEMU process crash) by unsetting vring alignment while updating Virtio rings. Scope: local bookworm: resolved (fixed in 1:2.11+dfsg-1) bullseye: resolved (fixed in 1:2.11+dfsg-1) forky: resolved (fixed in 1:2.11+dfsg-1) sid: resolved (fixed in 1:
debian
CVE-2017-9330P4MEDIUMCVSS 6.5fixed in qemu 1:2.8+dfsg-7 (bookworm)2017
CVE-2017-9330 [MEDIUM] CVE-2017-9330: qemu - QEMU (aka Quick Emulator) before 2.9.0, when built with the USB OHCI Emulation s... QEMU (aka Quick Emulator) before 2.9.0, when built with the USB OHCI Emulation support, allows local guest OS users to cause a denial of service (infinite loop) by leveraging an incorrect return value, a different vulnerability than CVE-2017-6505. Scope: local bookworm: resolved (fixed in 1:2.8+dfsg-7) bullseye: resolved (fixed in 1:2.8+dfsg-7) forky: resolved (fixed i
debian
CVE-2018-5683P4MEDIUMCVSS 6.0fixed in qemu 1:2.12~rc3+dfsg-1 (bookworm)2018
CVE-2018-5683 [MEDIUM] CVE-2018-5683: qemu - The vga_draw_text function in Qemu allows local OS guest privileged users to cau... The vga_draw_text function in Qemu allows local OS guest privileged users to cause a denial of service (out-of-bounds read and QEMU process crash) by leveraging improper memory address validation. Scope: local bookworm: resolved (fixed in 1:2.12~rc3+dfsg-1) bullseye: resolved (fixed in 1:2.12~rc3+dfsg-1) forky: resolved (fixed in 1:2.12~rc3+dfsg-1) sid: resolved (fixed
debian
CVE-2016-8910P4MEDIUMCVSS 6.0fixed in qemu 1:2.8+dfsg-1 (bookworm)2016
CVE-2016-8910 [MEDIUM] CVE-2016-8910: qemu - The rtl8139_cplus_transmit function in hw/net/rtl8139.c in QEMU (aka Quick Emula... The rtl8139_cplus_transmit function in hw/net/rtl8139.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and CPU consumption) by leveraging failure to limit the ring descriptor count. Scope: local bookworm: resolved (fixed in 1:2.8+dfsg-1) bullseye: resolved (fixed in 1:2.8+dfsg-1) forky: resolved (fixed in 1
debian
CVE-2016-2841P4MEDIUMCVSS 6.0fixed in qemu 1:2.6+dfsg-1 (bookworm)2016
CVE-2016-2841 [MEDIUM] CVE-2016-2841: qemu - The ne2000_receive function in the NE2000 NIC emulation support (hw/net/ne2000.c... The ne2000_receive function in the NE2000 NIC emulation support (hw/net/ne2000.c) in QEMU before 2.5.1 allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) via crafted values for the PSTART and PSTOP registers, involving ring buffer control. Scope: local bookworm: resolved (fixed in 1:2.6+dfsg-1) bullseye: resolved (f
debian
CVE-2016-8576P4MEDIUMCVSS 6.0fixed in qemu 1:2.8+dfsg-1 (bookworm)2016
CVE-2016-8576 [MEDIUM] CVE-2016-8576: qemu - The xhci_ring_fetch function in hw/usb/hcd-xhci.c in QEMU (aka Quick Emulator) a... The xhci_ring_fetch function in hw/usb/hcd-xhci.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) by leveraging failure to limit the number of link Transfer Request Blocks (TRB) to process. Scope: local bookworm: resolved (fixed in 1:2.8+dfsg-1) bullseye: resolved (fixed in 1:2.8+dfsg
debian
CVE-2016-5106P4MEDIUMCVSS 6.0fixed in qemu 1:2.6+dfsg-2 (bookworm)2016
CVE-2016-5106 [MEDIUM] CVE-2016-5106: qemu - The megasas_dcmd_set_properties function in hw/scsi/megasas.c in QEMU, when buil... The megasas_dcmd_set_properties function in hw/scsi/megasas.c in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, allows local guest administrators to cause a denial of service (out-of-bounds write access) via vectors involving a MegaRAID Firmware Interface (MFI) command. Scope: local bookworm: resolved (fixed in 1:2.6+dfsg-2) bullseye: re
debian
CVE-2021-4158P4MEDIUMCVSS 6.0fixed in qemu 1:6.2+dfsg-2 (bookworm)2021
CVE-2021-4158 [MEDIUM] CVE-2021-4158: qemu - A NULL pointer dereference issue was found in the ACPI code of QEMU. A malicious... A NULL pointer dereference issue was found in the ACPI code of QEMU. A malicious, privileged user within the guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition. Scope: local bookworm: resolved (fixed in 1:6.2+dfsg-2) bullseye: resolved forky: resolved (fixed in 1:6.2+dfsg-2) sid: resolved (fixed in 1:6.2+dfsg-2)
debian
Debian Qemu vulnerabilities | cvebase