Debian Qemu vulnerabilities
424 known vulnerabilities affecting debian/qemu.
Total CVEs
424
CISA KEV
0
Public exploits
7
Exploited in wild
0
Severity breakdown
CRITICAL10HIGH85MEDIUM226LOW102UNKNOWN1
Vulnerabilities
Page 2 of 22
CVE-2018-20815P3CRITICALCVSS 9.8fixed in qemu 1:3.1+dfsg-7 (bookworm)2018
CVE-2018-20815 [CRITICAL] CVE-2018-20815: qemu - In QEMU 3.1.0, load_device_tree in device_tree.c calls the deprecated load_image...
In QEMU 3.1.0, load_device_tree in device_tree.c calls the deprecated load_image function, which has a buffer overflow risk.
Scope: local
bookworm: resolved (fixed in 1:3.1+dfsg-7)
bullseye: resolved (fixed in 1:3.1+dfsg-7)
forky: resolved (fixed in 1:3.1+dfsg-7)
sid: resolved (fixed in 1:3.1+dfsg-7)
trixie: resolved (fixed in 1:3.1+dfsg-7)
debian
CVE-2012-6075P3CRITICALCVSS 9.3fixed in qemu 1.1.2+dfsg-4 (bookworm)2012
CVE-2012-6075 [CRITICAL] CVE-2012-6075: qemu - Buffer overflow in the e1000_receive function in the e1000 device driver (hw/e10...
Buffer overflow in the e1000_receive function in the e1000 device driver (hw/e1000.c) in QEMU 1.3.0-rc2 and other versions, when the SBP and LPE flags are disabled, allows remote attackers to cause a denial of service (guest OS crash) and possibly execute arbitrary guest code via a large packet.
Scope: local
bookworm: resolved (fixed in 1.1.2+dfsg-4)
bullseye: resolv
debian
CVE-2017-16845P3CRITICALCVSS 10.0fixed in qemu 1:2.12~rc3+dfsg-1 (bookworm)2017
CVE-2017-16845 [CRITICAL] CVE-2017-16845: qemu - hw/input/ps2.c in Qemu does not validate 'rptr' and 'count' values during guest ...
hw/input/ps2.c in Qemu does not validate 'rptr' and 'count' values during guest migration, leading to out-of-bounds access.
Scope: local
bookworm: resolved (fixed in 1:2.12~rc3+dfsg-1)
bullseye: resolved (fixed in 1:2.12~rc3+dfsg-1)
forky: resolved (fixed in 1:2.12~rc3+dfsg-1)
sid: resolved (fixed in 1:2.12~rc3+dfsg-1)
trixie: resolved (fixed in 1:2.12~rc3+dfsg-1)
debian
CVE-2017-8380P3CRITICALCVSS 9.8fixed in qemu 1:2.8+dfsg-5 (bookworm)2017
CVE-2017-8380 [CRITICAL] CVE-2017-8380: qemu - Buffer overflow in the "megasas_mmio_write" function in Qemu 2.9.0 allows remote...
Buffer overflow in the "megasas_mmio_write" function in Qemu 2.9.0 allows remote attackers to have unspecified impact via unknown vectors.
Scope: local
bookworm: resolved (fixed in 1:2.8+dfsg-5)
bullseye: resolved (fixed in 1:2.8+dfsg-5)
forky: resolved (fixed in 1:2.8+dfsg-5)
sid: resolved (fixed in 1:2.8+dfsg-5)
trixie: resolved (fixed in 1:2.8+dfsg-5)
debian
CVE-2008-2382P4MEDIUMCVSS 5.0PoCfixed in qemu 0.9.1-9 (bookworm)2008
CVE-2008-2382 [MEDIUM] CVE-2008-2382: qemu - The protocol_client_msg function in vnc.c in the VNC server in (1) Qemu 0.9.1 an...
The protocol_client_msg function in vnc.c in the VNC server in (1) Qemu 0.9.1 and earlier and (2) KVM kvm-79 and earlier allows remote attackers to cause a denial of service (infinite loop) via a certain message.
Scope: local
bookworm: resolved (fixed in 0.9.1-9)
bullseye: resolved (fixed in 0.9.1-9)
forky: resolved (fixed in 0.9.1-9)
sid: resolved (fixed in 0.9.1-9)
t
debian
CVE-2013-4542P3LOWCVSS 7.5fixed in qemu 2.1+dfsg-1 (bookworm)2013
CVE-2013-4542 [HIGH] CVE-2013-4542: qemu - The virtio_scsi_load_request function in hw/scsi/scsi-bus.c in QEMU before 1.7.2...
The virtio_scsi_load_request function in hw/scsi/scsi-bus.c in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via a crafted savevm image, which triggers an out-of-bounds array access.
Scope: local
bookworm: resolved (fixed in 2.1+dfsg-1)
bullseye: resolved (fixed in 2.1+dfsg-1)
forky: resolved (fixed in 2.1+dfsg-1)
sid: resolved (fixed in 2.1+df
debian
CVE-2016-4001P3HIGHCVSS 8.6fixed in qemu 1:2.6+dfsg-1 (bookworm)2016
CVE-2016-4001 [HIGH] CVE-2016-4001: qemu - Buffer overflow in the stellaris_enet_receive function in hw/net/stellaris_enet....
Buffer overflow in the stellaris_enet_receive function in hw/net/stellaris_enet.c in QEMU, when the Stellaris ethernet controller is configured to accept large packets, allows remote attackers to cause a denial of service (QEMU crash) via a large packet.
Scope: local
bookworm: resolved (fixed in 1:2.6+dfsg-1)
bullseye: resolved (fixed in 1:2.6+dfsg-1)
forky: resolved (fi
debian
CVE-2013-4535P3LOWCVSS 8.8fixed in qemu 2.1+dfsg-1 (bookworm)2013
CVE-2013-4535 [HIGH] CVE-2013-4535: qemu - The virtqueue_map_sg function in hw/virtio/virtio.c in QEMU before 1.7.2 allows ...
The virtqueue_map_sg function in hw/virtio/virtio.c in QEMU before 1.7.2 allows remote attackers to execute arbitrary files via a crafted savevm image, related to virtio-block or virtio-serial read.
Scope: local
bookworm: resolved (fixed in 2.1+dfsg-1)
bullseye: resolved (fixed in 2.1+dfsg-1)
forky: resolved (fixed in 2.1+dfsg-1)
sid: resolved (fixed in 2.1+dfsg-1)
trixi
debian
CVE-2016-3710P3HIGHCVSS 8.8fixed in qemu 1:2.6+dfsg-1 (bookworm)2016
CVE-2016-3710 [HIGH] CVE-2016-3710: qemu - The VGA module in QEMU improperly performs bounds checking on banked access to v...
The VGA module in QEMU improperly performs bounds checking on banked access to video memory, which allows local guest OS administrators to execute arbitrary code on the host by changing access modes after setting the bank register, aka the "Dark Portal" issue.
Scope: local
bookworm: resolved (fixed in 1:2.6+dfsg-1)
bullseye: resolved (fixed in 1:2.6+dfsg-1)
forky: resolv
debian
CVE-2014-7840P3LOWCVSS 7.5fixed in qemu 2.1+dfsg-8 (bookworm)2014
CVE-2014-7840 [HIGH] CVE-2014-7840: qemu - The host_from_stream_offset function in arch_init.c in QEMU, when loading RAM du...
The host_from_stream_offset function in arch_init.c in QEMU, when loading RAM during migration, allows remote attackers to execute arbitrary code via a crafted (1) offset or (2) length value in savevm data.
Scope: local
bookworm: resolved (fixed in 2.1+dfsg-8)
bullseye: resolved (fixed in 2.1+dfsg-8)
forky: resolved (fixed in 2.1+dfsg-8)
sid: resolved (fixed in 2.1+dfsg-
debian
CVE-2022-1050P3HIGHCVSS 8.8fixed in qemu 1:7.1+dfsg-2 (bookworm)2022
CVE-2022-1050 [HIGH] CVE-2022-1050: qemu - A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device....
A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device. This flaw allows a crafted guest driver to execute HW commands when shared buffers are not yet allocated, potentially leading to a use-after-free condition.
Scope: local
bookworm: resolved (fixed in 1:7.1+dfsg-2)
bullseye: resolved (fixed in 1:5.2+dfsg-11+deb11u3)
forky: resolved (fixed in 1
debian
CVE-2016-1714P3HIGHCVSS 8.1fixed in qemu 1:2.5+dfsg-4 (bookworm)2016
CVE-2016-1714 [HIGH] CVE-2016-1714: qemu - The (1) fw_cfg_write and (2) fw_cfg_read functions in hw/nvram/fw_cfg.c in QEMU ...
The (1) fw_cfg_write and (2) fw_cfg_read functions in hw/nvram/fw_cfg.c in QEMU before 2.4, when built with the Firmware Configuration device emulation support, allow guest OS users with the CAP_SYS_RAWIO privilege to cause a denial of service (out-of-bounds read or write access and process crash) or possibly execute arbitrary code via an invalid current entry value in a
debian
CVE-2014-0182P3HIGHCVSS 7.5fixed in qemu 2.1+dfsg-1 (bookworm)2014
CVE-2014-0182 [HIGH] CVE-2014-0182: qemu - Heap-based buffer overflow in the virtio_load function in hw/virtio/virtio.c in ...
Heap-based buffer overflow in the virtio_load function in hw/virtio/virtio.c in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via a crafted config length in a savevm image.
Scope: local
bookworm: resolved (fixed in 2.1+dfsg-1)
bullseye: resolved (fixed in 2.1+dfsg-1)
forky: resolved (fixed in 2.1+dfsg-1)
sid: resolved (fixed in 2.1+dfsg-1)
trix
debian
CVE-2017-15119P3MEDIUMCVSS 5.8fixed in qemu 1:2.11+dfsg-1 (bookworm)2017
CVE-2017-15119 [MEDIUM] CVE-2017-15119: qemu - The Network Block Device (NBD) server in Quick Emulator (QEMU) before 2.11 is vu...
The Network Block Device (NBD) server in Quick Emulator (QEMU) before 2.11 is vulnerable to a denial of service issue. It could occur if a client sent large option requests, making the server waste CPU time on reading up to 4GB per request. A client could use this flaw to keep the NBD server from serving other requests, resulting in DoS.
Scope: local
bookworm: resolv
debian
CVE-2013-4541P3LOWCVSS 7.5fixed in qemu 2.1+dfsg-1 (bookworm)2013
CVE-2013-4541 [HIGH] CVE-2013-4541: qemu - The usb_device_post_load function in hw/usb/bus.c in QEMU before 1.7.2 might all...
The usb_device_post_load function in hw/usb/bus.c in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via a crafted savevm image, related to a negative setup_len or setup_index value.
Scope: local
bookworm: resolved (fixed in 2.1+dfsg-1)
bullseye: resolved (fixed in 2.1+dfsg-1)
forky: resolved (fixed in 2.1+dfsg-1)
sid: resolved (fixed in 2.1+dfsg
debian
CVE-2017-14167P3HIGHCVSS 8.8fixed in qemu 1:2.10.0-1 (bookworm)2017
CVE-2017-14167 [HIGH] CVE-2017-14167: qemu - Integer overflow in the load_multiboot function in hw/i386/multiboot.c in QEMU (...
Integer overflow in the load_multiboot function in hw/i386/multiboot.c in QEMU (aka Quick Emulator) allows local guest OS users to execute arbitrary code on the host via crafted multiboot header address values, which trigger an out-of-bounds write.
Scope: local
bookworm: resolved (fixed in 1:2.10.0-1)
bullseye: resolved (fixed in 1:2.10.0-1)
forky: resolved (fixed in 1
debian
CVE-2014-0144P3HIGHCVSS 8.6fixed in qemu 2.0.0+dfsg-1 (bookworm)2014
CVE-2014-0144 [HIGH] CVE-2014-0144: qemu - QEMU before 2.0.0 block drivers for CLOOP, QCOW2 version 2 and various other ima...
QEMU before 2.0.0 block drivers for CLOOP, QCOW2 version 2 and various other image formats are vulnerable to potential memory corruptions, integer/buffer overflows or crash caused by missing input validations which could allow a remote user to execute arbitrary code on the host with the privileges of the QEMU process.
Scope: local
bookworm: resolved (fixed in 2.0.0+dfsg-
debian
CVE-2025-11234P3HIGHCVSS 7.5fixed in qemu 1:7.2+dfsg-7+deb12u18 (bookworm)2025
CVE-2025-11234 [HIGH] CVE-2025-11234: qemu - A flaw was found in QEMU. If the QIOChannelWebsock object is freed while it is w...
A flaw was found in QEMU. If the QIOChannelWebsock object is freed while it is waiting to complete a handshake, a GSource is leaked. This can lead to the callback firing later on and triggering a use-after-free in the use of the channel. This can be abused by a malicious client with network access to the VNC WebSocket port to cause a denial of service during the WebSoc
debian
CVE-2013-4149P3LOWCVSS 7.5fixed in qemu 2.1+dfsg-1 (bookworm)2013
CVE-2013-4149 [HIGH] CVE-2013-4149: qemu - Buffer overflow in virtio_net_load function in net/virtio-net.c in QEMU 1.3.0 th...
Buffer overflow in virtio_net_load function in net/virtio-net.c in QEMU 1.3.0 through 1.7.x before 1.7.2 might allow remote attackers to execute arbitrary code via a large MAC table.
Scope: local
bookworm: resolved (fixed in 2.1+dfsg-1)
bullseye: resolved (fixed in 2.1+dfsg-1)
forky: resolved (fixed in 2.1+dfsg-1)
sid: resolved (fixed in 2.1+dfsg-1)
trixie: resolved (fix
debian
CVE-2013-4148P3LOWCVSS 7.5fixed in qemu 2.1+dfsg-1 (bookworm)2013
CVE-2013-4148 [HIGH] CVE-2013-4148: qemu - Integer signedness error in the virtio_net_load function in hw/net/virtio-net.c ...
Integer signedness error in the virtio_net_load function in hw/net/virtio-net.c in QEMU 1.x before 1.7.2 allows remote attackers to execute arbitrary code via a crafted savevm image, which triggers a buffer overflow.
Scope: local
bookworm: resolved (fixed in 2.1+dfsg-1)
bullseye: resolved (fixed in 2.1+dfsg-1)
forky: resolved (fixed in 2.1+dfsg-1)
sid: resolved (fixed in
debian