Debian Qemu vulnerabilities
424 known vulnerabilities affecting debian/qemu.
Total CVEs
424
CISA KEV
0
Public exploits
7
Exploited in wild
0
Severity breakdown
CRITICAL10HIGH85MEDIUM226LOW102UNKNOWN1
Vulnerabilities
Page 4 of 22
CVE-2017-5931P3HIGHCVSS 8.8fixed in qemu 1:2.8+dfsg-3 (bookworm)2017
CVE-2017-5931 [HIGH] CVE-2017-5931: qemu - Integer overflow in hw/virtio/virtio-crypto.c in QEMU (aka Quick Emulator) allow...
Integer overflow in hw/virtio/virtio-crypto.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (QEMU process crash) or possibly execute arbitrary code on the host via a crafted virtio-crypto request, which triggers a heap-based buffer overflow.
Scope: local
bookworm: resolved (fixed in 1:2.8+dfsg-3)
bullseye: resolved (fixe
debian
CVE-2021-4206P3HIGHCVSS 8.2fixed in qemu 1:7.0+dfsg-1 (bookworm)2021
CVE-2021-4206 [HIGH] CVE-2021-4206: qemu - A flaw was found in the QXL display device emulation in QEMU. An integer overflo...
A flaw was found in the QXL display device emulation in QEMU. An integer overflow in the cursor_alloc() function can lead to the allocation of a small cursor object followed by a subsequent heap-based buffer overflow. This flaw allows a malicious privileged guest user to crash the QEMU process on the host or potentially execute arbitrary code within the context of the QE
debian
CVE-2021-3750P3HIGHCVSS 8.2fixed in qemu 1:7.0+dfsg-1 (bookworm)2021
CVE-2021-3750 [HIGH] CVE-2021-3750: qemu - A DMA reentrancy issue was found in the USB EHCI controller emulation of QEMU. E...
A DMA reentrancy issue was found in the USB EHCI controller emulation of QEMU. EHCI does not verify if the Buffer Pointer overlaps with its MMIO region when it transfers the USB packets. Crafted content may be written to the controller's registers and trigger undesirable actions (such as reset) while the device is still transferring packets. This can ultimately lead to a
debian
CVE-2013-2016P3HIGHCVSS 7.8fixed in qemu 1.5.0+dfsg-1 (bookworm)2013
CVE-2013-2016 [HIGH] CVE-2013-2016: qemu - A flaw was found in the way qemu v1.3.0 and later (virtio-rng) validates address...
A flaw was found in the way qemu v1.3.0 and later (virtio-rng) validates addresses when guest accesses the config space of a virtio device. If the virtio device has zero/small sized config space, such as virtio-rng, a privileged guest user could use this flaw to access the matching host's qemu address space and thus increase their privileges on the host.
Scope: local
boo
debian
CVE-2026-3842P3UNKNOWNfixed in qemu 1:10.2.2+ds-1 (forky)2026
CVE-2026-3842 CVE-2026-3842: qemu
bookworm: open
bullseye: resolved
forky: resolved (fixed in 1:10.2.2+ds-1)
sid: resolved (fixed in 1:10.2.2+ds-1)
trixie: open
debian
CVE-2013-4150P3LOWCVSS 7.5fixed in qemu 2.1+dfsg-1 (bookworm)2013
CVE-2013-4150 [HIGH] CVE-2013-4150: qemu - The virtio_net_load function in hw/net/virtio-net.c in QEMU 1.5.0 through 1.7.x ...
The virtio_net_load function in hw/net/virtio-net.c in QEMU 1.5.0 through 1.7.x before 1.7.2 allows remote attackers to cause a denial of service or possibly execute arbitrary code via vectors in which the value of curr_queues is greater than max_queues, which triggers an out-of-bounds write.
Scope: local
bookworm: resolved (fixed in 2.1+dfsg-1)
bullseye: resolved (fixed
debian
CVE-2020-1711P3HIGHCVSS 7.7fixed in qemu 1:4.2-2 (bookworm)2020
CVE-2020-1711 [HIGH] CVE-2020-1711: qemu - An out-of-bounds heap buffer access flaw was found in the way the iSCSI Block dr...
An out-of-bounds heap buffer access flaw was found in the way the iSCSI Block driver in QEMU versions 2.12.0 before 4.2.1 handled a response coming from an iSCSI server while checking the status of a Logical Address Block (LBA) in an iscsi_co_block_status() routine. A remote user could use this flaw to crash the QEMU process, resulting in a denial of service or potential
debian
CVE-2018-17962P3HIGHCVSS 7.5fixed in qemu 1:3.1+dfsg-1 (bookworm)2018
CVE-2018-17962 [HIGH] CVE-2018-17962: qemu - Qemu has a Buffer Overflow in pcnet_receive in hw/net/pcnet.c because an incorre...
Qemu has a Buffer Overflow in pcnet_receive in hw/net/pcnet.c because an incorrect integer data type is used.
Scope: local
bookworm: resolved (fixed in 1:3.1+dfsg-1)
bullseye: resolved (fixed in 1:3.1+dfsg-1)
forky: resolved (fixed in 1:3.1+dfsg-1)
sid: resolved (fixed in 1:3.1+dfsg-1)
trixie: resolved (fixed in 1:3.1+dfsg-1)
debian
CVE-2013-4534P3LOWCVSS 7.5fixed in qemu 2.1+dfsg-1 (bookworm)2013
CVE-2013-4534 [HIGH] CVE-2013-4534: qemu - Buffer overflow in hw/intc/openpic.c in QEMU before 1.7.2 allows remote attacker...
Buffer overflow in hw/intc/openpic.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service or possibly execute arbitrary code via vectors related to IRQDest elements.
Scope: local
bookworm: resolved (fixed in 2.1+dfsg-1)
bullseye: resolved (fixed in 2.1+dfsg-1)
forky: resolved (fixed in 2.1+dfsg-1)
sid: resolved (fixed in 2.1+dfsg-1)
trixie: resolved
debian
CVE-2016-1568P3HIGHCVSS 8.8fixed in qemu 1:2.5+dfsg-2 (bookworm)2016
CVE-2016-1568 [HIGH] CVE-2016-1568: qemu - Use-after-free vulnerability in hw/ide/ahci.c in QEMU, when built with IDE AHCI ...
Use-after-free vulnerability in hw/ide/ahci.c in QEMU, when built with IDE AHCI Emulation support, allows guest OS users to cause a denial of service (instance crash) or possibly execute arbitrary code via an invalid AHCI Native Command Queuing (NCQ) AIO command.
Scope: local
bookworm: resolved (fixed in 1:2.5+dfsg-2)
bullseye: resolved (fixed in 1:2.5+dfsg-2)
forky: res
debian
CVE-2019-20175P3LOWCVSS 7.5fixed in qemu 1:5.0-1 (bookworm)2019
CVE-2019-20175 [HIGH] CVE-2019-20175: qemu - An issue was discovered in ide_dma_cb() in hw/ide/core.c in QEMU 2.4.0 through 4...
An issue was discovered in ide_dma_cb() in hw/ide/core.c in QEMU 2.4.0 through 4.2.0. The guest system can crash the QEMU process in the host system via a special SCSI_IOCTL_SEND_COMMAND. It hits an assertion that implies that the size of successful DMA transfers there must be a multiple of 512 (the size of a sector). NOTE: a member of the QEMU security team disputes t
debian
CVE-2017-15124P3HIGHCVSS 7.5fixed in qemu 1:2.12~rc3+dfsg-1 (bookworm)2017
CVE-2017-15124 [HIGH] CVE-2017-15124: qemu - VNC server implementation in Quick Emulator (QEMU) 2.11.0 and older was found to...
VNC server implementation in Quick Emulator (QEMU) 2.11.0 and older was found to be vulnerable to an unbounded memory allocation issue, as it did not throttle the framebuffer updates sent to its client. If the client did not consume these updates, VNC server allocates growing memory to hold onto this data. A malicious remote VNC client could use this flaw to cause DoS
debian
CVE-2021-3929P3HIGHCVSS 8.2fixed in qemu 1:7.0+dfsg-1 (bookworm)2021
CVE-2021-3929 [HIGH] CVE-2021-3929: qemu - A DMA reentrancy issue was found in the NVM Express Controller (NVME) emulation ...
A DMA reentrancy issue was found in the NVM Express Controller (NVME) emulation in QEMU. This CVE is similar to CVE-2021-3750 and, just like it, when the reentrancy write triggers the reset function nvme_ctrl_reset(), data structs will be freed leading to a use-after-free issue. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a d
debian
CVE-2021-4207P3HIGHCVSS 8.2fixed in qemu 1:7.0+dfsg-1 (bookworm)2021
CVE-2021-4207 [HIGH] CVE-2021-4207: qemu - A flaw was found in the QXL display device emulation in QEMU. A double fetch of ...
A flaw was found in the QXL display device emulation in QEMU. A double fetch of guest controlled values `cursor->header.width` and `cursor->header.height` can lead to the allocation of a small cursor object followed by a subsequent heap-based buffer overflow. A malicious privileged guest user could use this flaw to crash the QEMU process on the host or potentially execut
debian
CVE-2024-3446P3HIGHCVSS 8.2fixed in qemu 1:7.2+dfsg-7+deb12u6 (bookworm)2024
CVE-2024-3446 [HIGH] CVE-2024-3446: qemu - A double free vulnerability was found in QEMU virtio devices (virtio-gpu, virtio...
A double free vulnerability was found in QEMU virtio devices (virtio-gpu, virtio-serial-bus, virtio-crypto), where the mem_reentrancy_guard flag insufficiently protects against DMA reentrancy issues. This issue could allow a malicious privileged guest user to crash the QEMU process on the host, resulting in a denial of service or allow arbitrary code execution within the
debian
CVE-2019-6778P3HIGHCVSS 7.8fixed in qemu 1:3.1+dfsg-3 (bookworm)2019
CVE-2019-6778 [HIGH] CVE-2019-6778: qemu - In QEMU 3.0.0, tcp_emu in slirp/tcp_subr.c has a heap-based buffer overflow.
In QEMU 3.0.0, tcp_emu in slirp/tcp_subr.c has a heap-based buffer overflow.
Scope: local
bookworm: resolved (fixed in 1:3.1+dfsg-3)
bullseye: resolved (fixed in 1:3.1+dfsg-3)
forky: resolved (fixed in 1:3.1+dfsg-3)
sid: resolved (fixed in 1:3.1+dfsg-3)
trixie: resolved (fixed in 1:3.1+dfsg-3)
debian
CVE-2018-16847P3HIGHCVSS 7.8fixed in qemu 1:3.1+dfsg-1 (bookworm)2018
CVE-2018-16847 [HIGH] CVE-2018-16847: qemu - An OOB heap buffer r/w access issue was found in the NVM Express Controller emul...
An OOB heap buffer r/w access issue was found in the NVM Express Controller emulation in QEMU. It could occur in nvme_cmb_ops routines in nvme device. A guest user/process could use this flaw to crash the QEMU process resulting in DoS or potentially run arbitrary code with privileges of the QEMU process.
Scope: local
bookworm: resolved (fixed in 1:3.1+dfsg-1)
bullseye:
debian
CVE-2013-4532P3LOWCVSS 7.8fixed in qemu 2.1+dfsg-1 (bookworm)2013
CVE-2013-4532 [HIGH] CVE-2013-4532: qemu - Qemu 1.1.2+dfsg to 2.1+dfsg suffers from a buffer overrun which could potentiall...
Qemu 1.1.2+dfsg to 2.1+dfsg suffers from a buffer overrun which could potentially result in arbitrary code execution on the host with the privileges of the QEMU process.
Scope: local
bookworm: resolved (fixed in 2.1+dfsg-1)
bullseye: resolved (fixed in 2.1+dfsg-1)
forky: resolved (fixed in 2.1+dfsg-1)
sid: resolved (fixed in 2.1+dfsg-1)
trixie: resolved (fixed in 2.1+dfs
debian
CVE-2018-16867P3HIGHCVSS 7.8fixed in qemu 1:3.1+dfsg-1 (bookworm)2018
CVE-2018-16867 [HIGH] CVE-2018-16867: qemu - A flaw was found in qemu Media Transfer Protocol (MTP) before version 3.1.0. A p...
A flaw was found in qemu Media Transfer Protocol (MTP) before version 3.1.0. A path traversal in the in usb_mtp_write_data function in hw/usb/dev-mtp.c due to an improper filename sanitization. When the guest device is mounted in read-write mode, this allows to read/write arbitrary files which may lead do DoS scenario OR possibly lead to code execution on the host.
Sco
debian
CVE-2022-2962P3HIGHCVSS 7.8fixed in qemu 1:7.1+dfsg-2 (bookworm)2022
CVE-2022-2962 [HIGH] CVE-2022-2962: qemu - A DMA reentrancy issue was found in the Tulip device emulation in QEMU. When Tul...
A DMA reentrancy issue was found in the Tulip device emulation in QEMU. When Tulip reads or writes to the rx/tx descriptor or copies the rx/tx frame, it doesn't check whether the destination address is its own MMIO address. This can cause the device to trigger MMIO handlers multiple times, possibly leading to a stack or heap overflow. A malicious guest could use this fla
debian