Debian Qemu vulnerabilities
424 known vulnerabilities affecting debian/qemu.
Total CVEs
424
CISA KEV
0
Public exploits
7
Exploited in wild
0
Severity breakdown
CRITICAL10HIGH85MEDIUM226LOW102UNKNOWN1
Vulnerabilities
Page 16 of 22
CVE-2020-35504P4MEDIUMCVSS 6.0fixed in qemu 1:6.0+dfsg-3 (bookworm)2020
CVE-2020-35504 [MEDIUM] CVE-2020-35504: qemu - A NULL pointer dereference flaw was found in the SCSI emulation support of QEMU ...
A NULL pointer dereference flaw was found in the SCSI emulation support of QEMU in versions before 6.0.0. This flaw allows a privileged guest user to crash the QEMU process on the host, resulting in a denial of service. The highest threat from this vulnerability is to system availability.
Scope: local
bookworm: resolved (fixed in 1:6.0+dfsg-3)
bullseye: open
forky: r
debian
CVE-2017-13672P4LOWCVSS 5.5fixed in qemu 1:2.10.0-1 (bookworm)2017
CVE-2017-13672 [MEDIUM] CVE-2017-13672: qemu - QEMU (aka Quick Emulator), when built with the VGA display emulator support, all...
QEMU (aka Quick Emulator), when built with the VGA display emulator support, allows local guest OS privileged users to cause a denial of service (out-of-bounds read and QEMU process crash) via vectors involving display update.
Scope: local
bookworm: resolved (fixed in 1:2.10.0-1)
bullseye: resolved (fixed in 1:2.10.0-1)
forky: resolved (fixed in 1:2.10.0-1)
sid: reso
debian
CVE-2018-19364P4MEDIUMCVSS 5.5fixed in qemu 1:3.1+dfsg-1 (bookworm)2018
CVE-2018-19364 [MEDIUM] CVE-2018-19364: qemu - hw/9pfs/cofile.c and hw/9pfs/9p.c in QEMU can modify an fid path while it is bei...
hw/9pfs/cofile.c and hw/9pfs/9p.c in QEMU can modify an fid path while it is being accessed by a second thread, leading to (for example) a use-after-free outcome.
Scope: local
bookworm: resolved (fixed in 1:3.1+dfsg-1)
bullseye: resolved (fixed in 1:3.1+dfsg-1)
forky: resolved (fixed in 1:3.1+dfsg-1)
sid: resolved (fixed in 1:3.1+dfsg-1)
trixie: resolved (fixed in 1:
debian
CVE-2017-7718P4MEDIUMCVSS 5.5fixed in qemu 1:2.8+dfsg-4 (bookworm)2017
CVE-2017-7718 [MEDIUM] CVE-2017-7718: qemu - hw/display/cirrus_vga_rop.h in QEMU (aka Quick Emulator) allows local guest OS p...
hw/display/cirrus_vga_rop.h in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (out-of-bounds read and QEMU process crash) via vectors related to copying VGA data via the cirrus_bitblt_rop_fwd_transp_ and cirrus_bitblt_rop_fwd_ functions.
Scope: local
bookworm: resolved (fixed in 1:2.8+dfsg-4)
bullseye: resolved (fixed in 1
debian
CVE-2016-4037P4MEDIUMCVSS 5.5fixed in qemu 1:2.6+dfsg-1 (bookworm)2016
CVE-2016-4037 [MEDIUM] CVE-2016-4037: qemu - The ehci_advance_state function in hw/usb/hcd-ehci.c in QEMU allows local guest ...
The ehci_advance_state function in hw/usb/hcd-ehci.c in QEMU allows local guest OS administrators to cause a denial of service (infinite loop and CPU consumption) via a circular split isochronous transfer descriptor (siTD) list, a related issue to CVE-2015-8558.
Scope: local
bookworm: resolved (fixed in 1:2.6+dfsg-1)
bullseye: resolved (fixed in 1:2.6+dfsg-1)
forky: re
debian
CVE-2017-9375P4MEDIUMCVSS 5.5fixed in qemu 1:2.10.0-1 (bookworm)2017
CVE-2017-9375 [MEDIUM] CVE-2017-9375: qemu - QEMU (aka Quick Emulator), when built with USB xHCI controller emulator support,...
QEMU (aka Quick Emulator), when built with USB xHCI controller emulator support, allows local guest OS privileged users to cause a denial of service (infinite recursive call) via vectors involving control transfer descriptors sequencing.
Scope: local
bookworm: resolved (fixed in 1:2.10.0-1)
bullseye: resolved (fixed in 1:2.10.0-1)
forky: resolved (fixed in 1:2.10.0-1)
debian
CVE-2016-2197P4MEDIUMCVSS 5.5fixed in qemu 1:2.6+dfsg-1 (bookworm)2016
CVE-2016-2197 [MEDIUM] CVE-2016-2197: qemu - QEMU (aka Quick Emulator) built with an IDE AHCI emulation support is vulnerable...
QEMU (aka Quick Emulator) built with an IDE AHCI emulation support is vulnerable to a null pointer dereference flaw. It occurs while unmapping the Frame Information Structure (FIS) and Command List Block (CLB) entries. A privileged user inside guest could use this flaw to crash the QEMU process instance resulting in DoS.
Scope: local
bookworm: resolved (fixed in 1:2.6+
debian
CVE-2016-2198P4MEDIUMCVSS 5.5fixed in qemu 1:2.6+dfsg-1 (bookworm)2016
CVE-2016-2198 [MEDIUM] CVE-2016-2198: qemu - QEMU (aka Quick Emulator) built with the USB EHCI emulation support is vulnerabl...
QEMU (aka Quick Emulator) built with the USB EHCI emulation support is vulnerable to a null pointer dereference flaw. It could occur when an application attempts to write to EHCI capabilities registers. A privileged user inside quest could use this flaw to crash the QEMU process instance resulting in DoS.
Scope: local
bookworm: resolved (fixed in 1:2.6+dfsg-1)
bullseye
debian
CVE-2016-10029P4MEDIUMCVSS 5.5fixed in qemu 1:2.7+dfsg-1 (bookworm)2016
CVE-2016-10029 [MEDIUM] CVE-2016-10029: qemu - The virtio_gpu_set_scanout function in QEMU (aka Quick Emulator) built with Virt...
The virtio_gpu_set_scanout function in QEMU (aka Quick Emulator) built with Virtio GPU Device emulator support allows local guest OS users to cause a denial of service (out-of-bounds read and process crash) via a scanout id in a VIRTIO_GPU_CMD_SET_SCANOUT command larger than num_scanouts.
Scope: local
bookworm: resolved (fixed in 1:2.7+dfsg-1)
bullseye: resolved (fix
debian
CVE-2017-9060P4LOWCVSS 5.5fixed in qemu 1:2.10.0-1 (bookworm)2017
CVE-2017-9060 [MEDIUM] CVE-2017-9060: qemu - Memory leak in the virtio_gpu_set_scanout function in hw/display/virtio-gpu.c in...
Memory leak in the virtio_gpu_set_scanout function in hw/display/virtio-gpu.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a denial of service (memory consumption) via a large number of "VIRTIO_GPU_CMD_SET_SCANOUT:" commands.
Scope: local
bookworm: resolved (fixed in 1:2.10.0-1)
bullseye: resolved (fixed in 1:2.10.0-1)
forky: resolved (fixed in 1:2
debian
CVE-2015-8745P4MEDIUMCVSS 5.5fixed in qemu 1:2.5+dfsg-1 (bookworm)2015
CVE-2015-8745 [MEDIUM] CVE-2015-8745: qemu - QEMU (aka Quick Emulator) built with a VMWARE VMXNET3 paravirtual NIC emulator s...
QEMU (aka Quick Emulator) built with a VMWARE VMXNET3 paravirtual NIC emulator support is vulnerable to crash issue. It could occur while reading Interrupt Mask Registers (IMR). A privileged (CAP_SYS_RAWIO) guest user could use this flaw to crash the QEMU process instance resulting in DoS.
Scope: local
bookworm: resolved (fixed in 1:2.5+dfsg-1)
bullseye: resolved (fixe
debian
CVE-2014-3471P4MEDIUMCVSS 5.5fixed in qemu 2.1+dfsg-1 (bookworm)2014
CVE-2014-3471 [MEDIUM] CVE-2014-3471: qemu - Use-after-free vulnerability in hw/pci/pcie.c in QEMU (aka Quick Emulator) allow...
Use-after-free vulnerability in hw/pci/pcie.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a denial of service (QEMU instance crash) via hotplug and hotunplug operations of Virtio block devices.
Scope: local
bookworm: resolved (fixed in 2.1+dfsg-1)
bullseye: resolved (fixed in 2.1+dfsg-1)
forky: resolved (fixed in 2.1+dfsg-1)
sid: resolved (fixed i
debian
CVE-2015-8744P4MEDIUMCVSS 5.5fixed in qemu 1:2.5+dfsg-1 (bookworm)2015
CVE-2015-8744 [MEDIUM] CVE-2015-8744: qemu - QEMU (aka Quick Emulator) built with a VMWARE VMXNET3 paravirtual NIC emulator s...
QEMU (aka Quick Emulator) built with a VMWARE VMXNET3 paravirtual NIC emulator support is vulnerable to crash issue. It occurs when a guest sends a Layer-2 packet smaller than 22 bytes. A privileged (CAP_SYS_RAWIO) guest user could use this flaw to crash the QEMU process instance resulting in DoS.
Scope: local
bookworm: resolved (fixed in 1:2.5+dfsg-1)
bullseye: resolv
debian
CVE-2026-2243P4MEDIUMCVSS 5.1fixed in qemu 1:10.2.2+ds-1 (forky)2026
CVE-2026-2243 [MEDIUM] CVE-2026-2243: qemu - A flaw was found in QEMU. A specially crafted VMDK image could trigger an out-of...
A flaw was found in QEMU. A specially crafted VMDK image could trigger an out-of-bounds read vulnerability, potentially leading to a 12-byte leak of sensitive information or a denial of service condition (DoS).
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1:10.2.2+ds-1)
sid: resolved (fixed in 1:10.2.2+ds-1)
trixie: open
debian
CVE-2015-8345P4MEDIUMCVSS 6.5fixed in qemu 1:2.5+dfsg-1 (bookworm)2015
CVE-2015-8345 [MEDIUM] CVE-2015-8345: qemu - The eepro100 emulator in QEMU qemu-kvm blank allows local guest users to cause a...
The eepro100 emulator in QEMU qemu-kvm blank allows local guest users to cause a denial of service (application crash and infinite loop) via vectors involving the command block list.
Scope: local
bookworm: resolved (fixed in 1:2.5+dfsg-1)
bullseye: resolved (fixed in 1:2.5+dfsg-1)
forky: resolved (fixed in 1:2.5+dfsg-1)
sid: resolved (fixed in 1:2.5+dfsg-1)
trixie: res
debian
CVE-2016-5107P4MEDIUMCVSS 6.0fixed in qemu 1:2.6+dfsg-2 (bookworm)2016
CVE-2016-5107 [MEDIUM] CVE-2016-5107: qemu - The megasas_lookup_frame function in QEMU, when built with MegaRAID SAS 8708EM2 ...
The megasas_lookup_frame function in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, allows local guest OS administrators to cause a denial of service (out-of-bounds read and crash) via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 1:2.6+dfsg-2)
bullseye: resolved (fixed in 1:2.6+dfsg-2)
forky: resolved (fixed in 1:2.6+df
debian
CVE-2016-7466P4MEDIUMCVSS 6.0fixed in qemu 1:2.7+dfsg-1 (bookworm)2016
CVE-2016-7466 [MEDIUM] CVE-2016-7466: qemu - Memory leak in the usb_xhci_exit function in hw/usb/hcd-xhci.c in QEMU (aka Quic...
Memory leak in the usb_xhci_exit function in hw/usb/hcd-xhci.c in QEMU (aka Quick Emulator), when the xhci uses msix, allows local guest OS administrators to cause a denial of service (memory consumption and possibly QEMU process crash) by repeatedly unplugging a USB device.
Scope: local
bookworm: resolved (fixed in 1:2.7+dfsg-1)
bullseye: resolved (fixed in 1:2.7+dfsg
debian
CVE-2016-10155P4LOWCVSS 6.0fixed in qemu 1:2.8+dfsg-2 (bookworm)2016
CVE-2016-10155 [MEDIUM] CVE-2016-10155: qemu - Memory leak in hw/watchdog/wdt_i6300esb.c in QEMU (aka Quick Emulator) allows lo...
Memory leak in hw/watchdog/wdt_i6300esb.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption and QEMU process crash) via a large number of device unplug operations.
Scope: local
bookworm: resolved (fixed in 1:2.8+dfsg-2)
bullseye: resolved (fixed in 1:2.8+dfsg-2)
forky: resolved (fixed in 1:2.8+df
debian
CVE-2016-8577P4MEDIUMCVSS 6.0fixed in qemu 1:2.8+dfsg-1 (bookworm)2016
CVE-2016-8577 [MEDIUM] CVE-2016-8577: qemu - Memory leak in the v9fs_read function in hw/9pfs/9p.c in QEMU (aka Quick Emulato...
Memory leak in the v9fs_read function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption) via vectors related to an I/O read operation.
Scope: local
bookworm: resolved (fixed in 1:2.8+dfsg-1)
bullseye: resolved (fixed in 1:2.8+dfsg-1)
forky: resolved (fixed in 1:2.8+dfsg-1)
sid: resolved (f
debian
CVE-2016-9101P4MEDIUMCVSS 6.0fixed in qemu 1:2.8+dfsg-1 (bookworm)2016
CVE-2016-9101 [MEDIUM] CVE-2016-9101: qemu - Memory leak in hw/net/eepro100.c in QEMU (aka Quick Emulator) allows local guest...
Memory leak in hw/net/eepro100.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption and QEMU process crash) by repeatedly unplugging an i8255x (PRO100) NIC device.
Scope: local
bookworm: resolved (fixed in 1:2.8+dfsg-1)
bullseye: resolved (fixed in 1:2.8+dfsg-1)
forky: resolved (fixed in 1:2.8+dfsg-1)
sid:
debian