Debian Qemu vulnerabilities
424 known vulnerabilities affecting debian/qemu.
Total CVEs
424
CISA KEV
0
Public exploits
7
Exploited in wild
0
Severity breakdown
CRITICAL10HIGH85MEDIUM226LOW102UNKNOWN1
Vulnerabilities
Page 3 of 22
CVE-2015-7504P3HIGHCVSS 8.8fixed in qemu 1:2.5+dfsg-1 (bookworm)2015
CVE-2015-7504 [HIGH] CVE-2015-7504: qemu - Heap-based buffer overflow in the pcnet_receive function in hw/net/pcnet.c in QE...
Heap-based buffer overflow in the pcnet_receive function in hw/net/pcnet.c in QEMU allows guest OS administrators to cause a denial of service (instance crash) or possibly execute arbitrary code via a series of packets in loopback mode.
Scope: local
bookworm: resolved (fixed in 1:2.5+dfsg-1)
bullseye: resolved (fixed in 1:2.5+dfsg-1)
forky: resolved (fixed in 1:2.5+dfsg-
debian
CVE-2013-6399P3LOWCVSS 7.5fixed in qemu 2.1+dfsg-1 (bookworm)2013
CVE-2013-6399 [HIGH] CVE-2013-6399: qemu - Array index error in the virtio_load function in hw/virtio/virtio.c in QEMU befo...
Array index error in the virtio_load function in hw/virtio/virtio.c in QEMU before 1.7.2 allows remote attackers to execute arbitrary code via a crafted savevm image.
Scope: local
bookworm: resolved (fixed in 2.1+dfsg-1)
bullseye: resolved (fixed in 2.1+dfsg-1)
forky: resolved (fixed in 2.1+dfsg-1)
sid: resolved (fixed in 2.1+dfsg-1)
trixie: resolved (fixed in 2.1+dfsg-1
debian
CVE-2018-7550P3HIGHCVSS 8.8fixed in qemu 1:2.12~rc3+dfsg-1 (bookworm)2018
CVE-2018-7550 [HIGH] CVE-2018-7550: qemu - The load_multiboot function in hw/i386/multiboot.c in Quick Emulator (aka QEMU) ...
The load_multiboot function in hw/i386/multiboot.c in Quick Emulator (aka QEMU) allows local guest OS users to execute arbitrary code on the QEMU host via a mh_load_end_addr value greater than mh_bss_end_addr, which triggers an out-of-bounds read or write memory access.
Scope: local
bookworm: resolved (fixed in 1:2.12~rc3+dfsg-1)
bullseye: resolved (fixed in 1:2.12~rc3+d
debian
CVE-2013-4537P3LOWCVSS 7.5fixed in qemu 2.1+dfsg-1 (bookworm)2013
CVE-2013-4537 [HIGH] CVE-2013-4537: qemu - The ssi_sd_transfer function in hw/sd/ssi-sd.c in QEMU before 1.7.2 allows remot...
The ssi_sd_transfer function in hw/sd/ssi-sd.c in QEMU before 1.7.2 allows remote attackers to execute arbitrary code via a crafted arglen value in a savevm image.
Scope: local
bookworm: resolved (fixed in 2.1+dfsg-1)
bullseye: resolved (fixed in 2.1+dfsg-1)
forky: resolved (fixed in 2.1+dfsg-1)
sid: resolved (fixed in 2.1+dfsg-1)
trixie: resolved (fixed in 2.1+dfsg-1)
debian
CVE-2024-7730P3HIGHCVSS 7.4fixed in qemu 1:9.1.0+ds-1 (forky)2024
CVE-2024-7730 [HIGH] CVE-2024-7730: qemu - A heap buffer overflow was found in the virtio-snd device in QEMU. When reading ...
A heap buffer overflow was found in the virtio-snd device in QEMU. When reading input audio in the virtio-snd input callback, virtio_snd_pcm_in_cb, the function did not check whether the iov can fit the data buffer. This issue can trigger an out-of-bounds write if the size of the virtio queue element is equal to virtio_snd_pcm_status, which makes the available space for
debian
CVE-2017-7471P3CRITICALCVSS 9.0fixed in qemu 1:2.8+dfsg-5 (bookworm)2017
CVE-2017-7471 [CRITICAL] CVE-2017-7471: qemu - Quick Emulator (Qemu) built with the VirtFS, host directory sharing via Plan 9 F...
Quick Emulator (Qemu) built with the VirtFS, host directory sharing via Plan 9 File System (9pfs) support, is vulnerable to an improper access control issue. It could occur while accessing files on a shared host directory. A privileged user inside guest could use this flaw to access host file system beyond the shared folder and potentially escalating their privileges
debian
CVE-2013-4540P3LOWCVSS 7.5fixed in qemu 2.1+dfsg-1 (bookworm)2013
CVE-2013-4540 [HIGH] CVE-2013-4540: qemu - Buffer overflow in scoop_gpio_handler_update in QEMU before 1.7.2 might allow re...
Buffer overflow in scoop_gpio_handler_update in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via a large (1) prev_level, (2) gpio_level, or (3) gpio_dir value in a savevm image.
Scope: local
bookworm: resolved (fixed in 2.1+dfsg-1)
bullseye: resolved (fixed in 2.1+dfsg-1)
forky: resolved (fixed in 2.1+dfsg-1)
sid: resolved (fixed in 2.1+dfsg-1
debian
CVE-2013-4539P3LOWCVSS 7.5fixed in qemu 2.1+dfsg-1 (bookworm)2013
CVE-2013-4539 [HIGH] CVE-2013-4539: qemu - Multiple buffer overflows in the tsc210x_load function in hw/input/tsc210x.c in ...
Multiple buffer overflows in the tsc210x_load function in hw/input/tsc210x.c in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via a crafted (1) precision, (2) nextprecision, (3) function, or (4) nextfunction value in a savevm image.
Scope: local
bookworm: resolved (fixed in 2.1+dfsg-1)
bullseye: resolved (fixed in 2.1+dfsg-1)
forky: resolved (f
debian
CVE-2015-1779P3HIGHCVSS 8.6fixed in qemu 1:2.3+dfsg-1 (bookworm)2015
CVE-2015-1779 [HIGH] CVE-2015-1779: qemu - The VNC websocket frame decoder in QEMU allows remote attackers to cause a denia...
The VNC websocket frame decoder in QEMU allows remote attackers to cause a denial of service (memory and CPU consumption) via a large (1) websocket payload or (2) HTTP headers section.
Scope: local
bookworm: resolved (fixed in 1:2.3+dfsg-1)
bullseye: resolved (fixed in 1:2.3+dfsg-1)
forky: resolved (fixed in 1:2.3+dfsg-1)
sid: resolved (fixed in 1:2.3+dfsg-1)
trixie: res
debian
CVE-2013-4536P3LOWCVSS 7.8fixed in qemu 2.1+dfsg-1 (bookworm)2013
CVE-2013-4536 [HIGH] CVE-2013-4536: qemu - An user able to alter the savevm data (either on the disk or over the wire durin...
An user able to alter the savevm data (either on the disk or over the wire during migration) could use this flaw to to corrupt QEMU process memory on the (destination) host, which could potentially result in arbitrary code execution on the host with the privileges of the QEMU process.
Scope: local
bookworm: resolved (fixed in 2.1+dfsg-1)
bullseye: resolved (fixed in 2.1+
debian
CVE-2018-17958P3HIGHCVSS 7.5fixed in qemu 1:3.1+dfsg-1 (bookworm)2018
CVE-2018-17958 [HIGH] CVE-2018-17958: qemu - Qemu has a Buffer Overflow in rtl8139_do_receive in hw/net/rtl8139.c because an ...
Qemu has a Buffer Overflow in rtl8139_do_receive in hw/net/rtl8139.c because an incorrect integer data type is used.
Scope: local
bookworm: resolved (fixed in 1:3.1+dfsg-1)
bullseye: resolved (fixed in 1:3.1+dfsg-1)
forky: resolved (fixed in 1:3.1+dfsg-1)
sid: resolved (fixed in 1:3.1+dfsg-1)
trixie: resolved (fixed in 1:3.1+dfsg-1)
debian
CVE-2013-4527P3LOWCVSS 7.5fixed in qemu 2.1+dfsg-1 (bookworm)2013
CVE-2013-4527 [HIGH] CVE-2013-4527: qemu - Buffer overflow in hw/timer/hpet.c in QEMU before 1.7.2 might allow remote attac...
Buffer overflow in hw/timer/hpet.c in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via vectors related to the number of timers.
Scope: local
bookworm: resolved (fixed in 2.1+dfsg-1)
bullseye: resolved (fixed in 2.1+dfsg-1)
forky: resolved (fixed in 2.1+dfsg-1)
sid: resolved (fixed in 2.1+dfsg-1)
trixie: resolved (fixed in 2.1+dfsg-1)
debian
CVE-2020-24165P3HIGHCVSS 8.8fixed in qemu 1:5.0-1 (bookworm)2020
CVE-2020-24165 [HIGH] CVE-2020-24165: qemu - An issue was discovered in TCG Accelerator in QEMU 4.2.0, allows local attackers...
An issue was discovered in TCG Accelerator in QEMU 4.2.0, allows local attackers to execute arbitrary code, escalate privileges, and cause a denial of service (DoS). Note: This is disputed as a bug and not a valid security issue by multiple third parties.
Scope: local
bookworm: resolved (fixed in 1:5.0-1)
bullseye: resolved (fixed in 1:5.0-1)
forky: resolved (fixed in
debian
CVE-2022-35414P3LOWCVSS 8.8fixed in qemu 1:7.1+dfsg-1 (bookworm)2022
CVE-2022-35414 [HIGH] CVE-2022-35414: qemu - softmmu/physmem.c in QEMU through 7.0.0 can perform an uninitialized read on the...
softmmu/physmem.c in QEMU through 7.0.0 can perform an uninitialized read on the translate_fail path, leading to an io_readx or io_writex crash. NOTE: a third party states that the Non-virtualization Use Case in the qemu.org reference applies here, i.e., "Bugs affecting the non-virtualization use case are not considered security bugs at this time.
Scope: local
bookworm
debian
CVE-2023-3354P3HIGHCVSS 7.5fixed in qemu 1:7.2+dfsg-7+deb12u2 (bookworm)2023
CVE-2023-3354 [HIGH] CVE-2023-3354: qemu - A flaw was found in the QEMU built-in VNC server. When a client connects to the ...
A flaw was found in the QEMU built-in VNC server. When a client connects to the VNC server, QEMU checks whether the current number of connections crosses a certain threshold and if so, cleans up the previous connection. If the previous connection happens to be in the handshake phase and fails, QEMU cleans up the connection again, resulting in a NULL pointer dereference i
debian
CVE-2024-4467P3HIGHCVSS 7.8fixed in qemu 1:7.2+dfsg-7+deb12u7 (bookworm)2024
CVE-2024-4467 [HIGH] CVE-2024-4467: qemu - A flaw was found in the QEMU disk image utility (qemu-img) 'info' command. A spe...
A flaw was found in the QEMU disk image utility (qemu-img) 'info' command. A specially crafted image file containing a `json:{}` value describing block devices in QMP could cause the qemu-img process on the host to consume large amounts of memory or CPU time, leading to denial of service or read/write to an existing external file.
Scope: local
bookworm: resolved (fixed i
debian
CVE-2022-0358P3HIGHCVSS 7.8fixed in qemu 1:7.0+dfsg-1 (bookworm)2022
CVE-2022-0358 [HIGH] CVE-2022-0358: qemu - A flaw was found in the QEMU virtio-fs shared file system daemon (virtiofsd) imp...
A flaw was found in the QEMU virtio-fs shared file system daemon (virtiofsd) implementation. This flaw is strictly related to CVE-2018-13405. A local guest user can create files in the directories shared by virtio-fs with unintended group ownership in a scenario where a directory is SGID to a certain group and is writable by a user who is not a member of the group. This
debian
CVE-2013-4530P3LOWCVSS 7.5fixed in qemu 2.1+dfsg-1 (bookworm)2013
CVE-2013-4530 [HIGH] CVE-2013-4530: qemu - Buffer overflow in hw/ssi/pl022.c in QEMU before 1.7.2 allows remote attackers t...
Buffer overflow in hw/ssi/pl022.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service or possibly execute arbitrary code via crafted tx_fifo_head and rx_fifo_head values in a savevm image.
Scope: local
bookworm: resolved (fixed in 2.1+dfsg-1)
bullseye: resolved (fixed in 2.1+dfsg-1)
forky: resolved (fixed in 2.1+dfsg-1)
sid: resolved (fixed in 2.1+d
debian
CVE-2013-4538P3LOWCVSS 7.5fixed in qemu 2.1+dfsg-1 (bookworm)2013
CVE-2013-4538 [HIGH] CVE-2013-4538: qemu - Multiple buffer overflows in the ssd0323_load function in hw/display/ssd0323.c i...
Multiple buffer overflows in the ssd0323_load function in hw/display/ssd0323.c in QEMU before 1.7.2 allow remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via crafted (1) cmd_len, (2) row, or (3) col values; (4) row_start and row_end values; or (5) col_star and col_end values in a savevm image.
Scope: local
bookworm: re
debian
CVE-2017-6058P3HIGHCVSS 7.5fixed in qemu 1:2.8+dfsg-3 (bookworm)2017
CVE-2017-6058 [HIGH] CVE-2017-6058: qemu - Buffer overflow in NetRxPkt::ehdr_buf in hw/net/net_rx_pkt.c in QEMU (aka Quick ...
Buffer overflow in NetRxPkt::ehdr_buf in hw/net/net_rx_pkt.c in QEMU (aka Quick Emulator), when the VLANSTRIP feature is enabled on the vmxnet3 device, allows remote attackers to cause a denial of service (out-of-bounds access and QEMU process crash) via vectors related to VLAN stripping.
Scope: local
bookworm: resolved (fixed in 1:2.8+dfsg-3)
bullseye: resolved (fixed i
debian