Debian Qemu vulnerabilities
424 known vulnerabilities affecting debian/qemu.
Total CVEs
424
CISA KEV
0
Public exploits
7
Exploited in wild
0
Severity breakdown
CRITICAL10HIGH85MEDIUM226LOW102UNKNOWN1
Vulnerabilities
Page 20 of 22
CVE-2013-1922P4LOWCVSS 4.9fixed in qemu 1.5.0+dfsg-1 (bookworm)2013
CVE-2013-1922 [MEDIUM] CVE-2013-1922: qemu - qemu-nbd in QEMU, as used in Xen 4.2.x, determines the format of a raw disk imag...
qemu-nbd in QEMU, as used in Xen 4.2.x, determines the format of a raw disk image based on the header, which allows local guest OS administrators to read arbitrary files on the host by modifying the header to identify a different format, which is used when the guest is restarted, a different vulnerability than CVE-2008-2004.
Scope: local
bookworm: resolved (fixed in 1.
debian
CVE-2014-5388P4MEDIUMCVSS 4.6fixed in qemu 2.1+dfsg-5 (bookworm)2014
CVE-2014-5388 [MEDIUM] CVE-2014-5388: qemu - Off-by-one error in the pci_read function in the ACPI PCI hotplug interface (hw/...
Off-by-one error in the pci_read function in the ACPI PCI hotplug interface (hw/acpi/pcihp.c) in QEMU allows local guest users to obtain sensitive information and have other unspecified impact related to a crafted PCI device that triggers memory corruption.
Scope: local
bookworm: resolved (fixed in 2.1+dfsg-5)
bullseye: resolved (fixed in 2.1+dfsg-5)
forky: resolved (f
debian
CVE-2008-1945P4LOWCVSS 2.1fixed in qemu 0.9.1-5 (bookworm)2008
CVE-2008-1945 [LOW] CVE-2008-1945: qemu - QEMU 0.9.0 does not properly handle changes to removable media, which allows gue...
QEMU 0.9.0 does not properly handle changes to removable media, which allows guest OS users to read arbitrary files on the host OS by using the diskformat: parameter in the -usbdevice option to modify the disk-image header to identify a different format, a related issue to CVE-2008-2004.
Scope: local
bookworm: resolved (fixed in 0.9.1-5)
bullseye: resolved (fixed in 0.9.1
debian
CVE-2016-7909P4MEDIUMCVSS 4.4fixed in qemu 1:2.8+dfsg-1 (bookworm)2016
CVE-2016-7909 [MEDIUM] CVE-2016-7909: qemu - The pcnet_rdra_addr function in hw/net/pcnet.c in QEMU (aka Quick Emulator) allo...
The pcnet_rdra_addr function in hw/net/pcnet.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) by setting the (1) receive or (2) transmit descriptor ring length to 0.
Scope: local
bookworm: resolved (fixed in 1:2.8+dfsg-1)
bullseye: resolved (fixed in 1:2.8+dfsg-1)
forky: resolved (fi
debian
CVE-2016-4453P4MEDIUMCVSS 4.4fixed in qemu 1:2.6+dfsg-3 (bookworm)2016
CVE-2016-4453 [MEDIUM] CVE-2016-4453: qemu - The vmsvga_fifo_run function in hw/display/vmware_vga.c in QEMU allows local gue...
The vmsvga_fifo_run function in hw/display/vmware_vga.c in QEMU allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) via a VGA command.
Scope: local
bookworm: resolved (fixed in 1:2.6+dfsg-3)
bullseye: resolved (fixed in 1:2.6+dfsg-3)
forky: resolved (fixed in 1:2.6+dfsg-3)
sid: resolved (fixed in 1:2.6+dfsg-3)
trixie
debian
CVE-2016-7421P4MEDIUMCVSS 4.4fixed in qemu 1:2.7+dfsg-1 (bookworm)2016
CVE-2016-7421 [MEDIUM] CVE-2016-7421: qemu - The pvscsi_ring_pop_req_descr function in hw/scsi/vmw_pvscsi.c in QEMU (aka Quic...
The pvscsi_ring_pop_req_descr function in hw/scsi/vmw_pvscsi.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) by leveraging failure to limit process IO loop to the ring size.
Scope: local
bookworm: resolved (fixed in 1:2.7+dfsg-1)
bullseye: resolved (fixed in 1:2.7+dfsg-1)
forky: res
debian
CVE-2016-7157P4MEDIUMCVSS 4.4fixed in qemu 1:2.6+dfsg-3.1 (bookworm)2016
CVE-2016-7157 [MEDIUM] CVE-2016-7157: qemu - The (1) mptsas_config_manufacturing_1 and (2) mptsas_config_ioc_0 functions in h...
The (1) mptsas_config_manufacturing_1 and (2) mptsas_config_ioc_0 functions in hw/scsi/mptconfig.c in QEMU (aka Quick Emulator) allow local guest OS administrators to cause a denial of service (QEMU process crash) via vectors involving MPTSAS_CONFIG_PACK.
Scope: local
bookworm: resolved (fixed in 1:2.6+dfsg-3.1)
bullseye: resolved (fixed in 1:2.6+dfsg-3.1)
forky: resol
debian
CVE-2016-7156P4MEDIUMCVSS 4.4fixed in qemu 1:2.6+dfsg-3.1 (bookworm)2016
CVE-2016-7156 [MEDIUM] CVE-2016-7156: qemu - The pvscsi_convert_sglist function in hw/scsi/vmw_pvscsi.c in QEMU (aka Quick Em...
The pvscsi_convert_sglist function in hw/scsi/vmw_pvscsi.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) by leveraging an incorrect cast.
Scope: local
bookworm: resolved (fixed in 1:2.6+dfsg-3.1)
bullseye: resolved (fixed in 1:2.6+dfsg-3.1)
forky: resolved (fixed in 1:2.6+dfsg-3.1)
debian
CVE-2016-6834P4MEDIUMCVSS 4.4fixed in qemu 1:2.6+dfsg-3.1 (bookworm)2016
CVE-2016-6834 [MEDIUM] CVE-2016-6834: qemu - The net_tx_pkt_do_sw_fragmentation function in hw/net/net_tx_pkt.c in QEMU (aka ...
The net_tx_pkt_do_sw_fragmentation function in hw/net/net_tx_pkt.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) via a zero length for the current fragment length.
Scope: local
bookworm: resolved (fixed in 1:2.6+dfsg-3.1)
bullseye: resolved (fixed in 1:2.6+dfsg-3.1)
forky: resolved
debian
CVE-2016-7155P4MEDIUMCVSS 4.4fixed in qemu 1:2.6+dfsg-3.1 (bookworm)2016
CVE-2016-7155 [MEDIUM] CVE-2016-7155: qemu - hw/scsi/vmw_pvscsi.c in QEMU (aka Quick Emulator) allows local guest OS administ...
hw/scsi/vmw_pvscsi.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (out-of-bounds access or infinite loop, and QEMU process crash) via a crafted page count for descriptor rings.
Scope: local
bookworm: resolved (fixed in 1:2.6+dfsg-3.1)
bullseye: resolved (fixed in 1:2.6+dfsg-3.1)
forky: resolved (fixed in 1:2.6+dfsg-3.1)
debian
CVE-2017-18030P4MEDIUMCVSS 4.4fixed in qemu 1:2.8+dfsg-4 (bookworm)2017
CVE-2017-18030 [MEDIUM] CVE-2017-18030: qemu - The cirrus_invalidate_region function in hw/display/cirrus_vga.c in Qemu allows ...
The cirrus_invalidate_region function in hw/display/cirrus_vga.c in Qemu allows local OS guest privileged users to cause a denial of service (out-of-bounds array access and QEMU process crash) via vectors related to negative pitch.
Scope: local
bookworm: resolved (fixed in 1:2.8+dfsg-4)
bullseye: resolved (fixed in 1:2.8+dfsg-4)
forky: resolved (fixed in 1:2.8+dfsg-4
debian
CVE-2016-6833P4MEDIUMCVSS 4.4fixed in qemu 1:2.6+dfsg-3.1 (bookworm)2016
CVE-2016-6833 [MEDIUM] CVE-2016-6833: qemu - Use-after-free vulnerability in the vmxnet3_io_bar0_write function in hw/net/vmx...
Use-after-free vulnerability in the vmxnet3_io_bar0_write function in hw/net/vmxnet3.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (QEMU instance crash) by leveraging failure to check if the device is active.
Scope: local
bookworm: resolved (fixed in 1:2.6+dfsg-3.1)
bullseye: resolved (fixed in 1:2.6+dfsg-3.1)
forky: r
debian
CVE-2019-12068P4LOWCVSS 3.8fixed in qemu 1:4.1-2 (bookworm)2019
CVE-2019-12068 [LOW] CVE-2019-12068: qemu - In QEMU 1:4.1-1, 1:2.1+dfsg-12+deb8u6, 1:2.8+dfsg-6+deb9u8, 1:3.1+dfsg-8~deb10u1...
In QEMU 1:4.1-1, 1:2.1+dfsg-12+deb8u6, 1:2.8+dfsg-6+deb9u8, 1:3.1+dfsg-8~deb10u1, 1:3.1+dfsg-8+deb10u2, and 1:2.1+dfsg-12+deb8u12 (fixed), when executing script in lsi_execute_script(), the LSI scsi adapter emulator advances 's->dsp' index to read next opcode. This can lead to an infinite loop if the next opcode is empty. Move the existing loop exit after 10k iterations
debian
CVE-2020-12829P4LOWCVSS 3.8fixed in qemu 1:5.0-12 (bookworm)2020
CVE-2020-12829 [LOW] CVE-2020-12829: qemu - In QEMU through 5.0.0, an integer overflow was found in the SM501 display driver...
In QEMU through 5.0.0, an integer overflow was found in the SM501 display driver implementation. This flaw occurs in the COPY_AREA macro while handling MMIO write operations through the sm501_2d_engine_write() callback. A local attacker could abuse this flaw to crash the QEMU process in sm501_2d_operation() in hw/display/sm501.c on the host, resulting in a denial of ser
debian
CVE-2015-6815P4LOWCVSS 3.5fixed in qemu 1:2.4+dfsg-2 (bookworm)2015
CVE-2015-6815 [LOW] CVE-2015-6815: qemu - The process_tx_desc function in hw/net/e1000.c in QEMU before 2.4.0.1 does not p...
The process_tx_desc function in hw/net/e1000.c in QEMU before 2.4.0.1 does not properly process transmit descriptor data when sending a network packet, which allows attackers to cause a denial of service (infinite loop and guest crash) via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 1:2.4+dfsg-2)
bullseye: resolved (fixed in 1:2.4+dfsg-2)
forky: resolve
debian
CVE-2025-8860P4LOWCVSS 3.3fixed in qemu 1:10.0.3+ds-4 (forky)2025
CVE-2025-8860 [LOW] CVE-2025-8860: qemu - A flaw was found in QEMU in the uefi-vars virtual device. When the guest writes ...
A flaw was found in QEMU in the uefi-vars virtual device. When the guest writes to register UEFI_VARS_REG_BUFFER_SIZE, the .write callback `uefi_vars_write` is invoked. The function allocates a heap buffer without zeroing the memory, leaving the buffer filled with residual data from prior allocations. When the guest later reads from register UEFI_VARS_REG_PIO_BUFFER_TRANS
debian
CVE-2016-9104P4MEDIUMCVSS 4.4fixed in qemu 1:2.8+dfsg-1 (bookworm)2016
CVE-2016-9104 [MEDIUM] CVE-2016-9104: qemu - Multiple integer overflows in the (1) v9fs_xattr_read and (2) v9fs_xattr_write f...
Multiple integer overflows in the (1) v9fs_xattr_read and (2) v9fs_xattr_write functions in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allow local guest OS administrators to cause a denial of service (QEMU process crash) via a crafted offset, which triggers an out-of-bounds access.
Scope: local
bookworm: resolved (fixed in 1:2.8+dfsg-1)
bullseye: resolved (fixed in 1:2.
debian
CVE-2016-6490P4MEDIUMCVSS 4.4fixed in qemu 1:2.6+dfsg-3.1 (bookworm)2016
CVE-2016-6490 [MEDIUM] CVE-2016-6490: qemu - The virtqueue_map_desc function in hw/virtio/virtio.c in QEMU (aka Quick Emulato...
The virtqueue_map_desc function in hw/virtio/virtio.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) via a zero length for the descriptor buffer.
Scope: local
bookworm: resolved (fixed in 1:2.6+dfsg-3.1)
bullseye: resolved (fixed in 1:2.6+dfsg-3.1)
forky: resolved (fixed in 1:2.6+dfs
debian
CVE-2016-6888P4MEDIUMCVSS 4.4fixed in qemu 1:2.6+dfsg-3.1 (bookworm)2016
CVE-2016-6888 [MEDIUM] CVE-2016-6888: qemu - Integer overflow in the net_tx_pkt_init function in hw/net/net_tx_pkt.c in QEMU ...
Integer overflow in the net_tx_pkt_init function in hw/net/net_tx_pkt.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (QEMU process crash) via the maximum fragmentation count, which triggers an unchecked multiplication and NULL pointer dereference.
Scope: local
bookworm: resolved (fixed in 1:2.6+dfsg-3.1)
bullseye: resol
debian
CVE-2020-29443P4LOWCVSS 3.9fixed in qemu 1:5.2+dfsg-11 (bookworm)2020
CVE-2020-29443 [LOW] CVE-2020-29443: qemu - ide_atapi_cmd_reply_end in hw/ide/atapi.c in QEMU 5.1.0 allows out-of-bounds rea...
ide_atapi_cmd_reply_end in hw/ide/atapi.c in QEMU 5.1.0 allows out-of-bounds read access because a buffer index is not validated.
Scope: local
bookworm: resolved (fixed in 1:5.2+dfsg-11)
bullseye: resolved (fixed in 1:5.2+dfsg-11)
forky: resolved (fixed in 1:5.2+dfsg-11)
sid: resolved (fixed in 1:5.2+dfsg-11)
trixie: resolved (fixed in 1:5.2+dfsg-11)
debian