Debian Qemu vulnerabilities
424 known vulnerabilities affecting debian/qemu.
Total CVEs
424
CISA KEV
0
Public exploits
7
Exploited in wild
0
Severity breakdown
CRITICAL10HIGH85MEDIUM226LOW102UNKNOWN1
Vulnerabilities
Page 5 of 22
CVE-2024-7409P3HIGHCVSS 7.5fixed in qemu 1:7.2+dfsg-7+deb12u8 (bookworm)2024
CVE-2024-7409 [HIGH] CVE-2024-7409: qemu - A flaw was found in the QEMU NBD Server. This vulnerability allows a denial of s...
A flaw was found in the QEMU NBD Server. This vulnerability allows a denial of service (DoS) attack via improper synchronization during socket closure when a client keeps a socket open as the server is taken offline.
Scope: local
bookworm: resolved (fixed in 1:7.2+dfsg-7+deb12u8)
bullseye: resolved (fixed in 1:5.2+dfsg-11+deb11u5)
forky: resolved (fixed in 1:9.0.2+ds-3)
debian
CVE-2014-3461P3MEDIUMCVSS 6.8fixed in qemu 2.1+dfsg-1 (bookworm)2014
CVE-2014-3461 [MEDIUM] CVE-2014-3461: qemu - hw/usb/bus.c in QEMU 1.6.2 allows remote attackers to execute arbitrary code via...
hw/usb/bus.c in QEMU 1.6.2 allows remote attackers to execute arbitrary code via crafted savevm data, which triggers a heap-based buffer overflow, related to "USB post load checks."
Scope: local
bookworm: resolved (fixed in 2.1+dfsg-1)
bullseye: resolved (fixed in 2.1+dfsg-1)
forky: resolved (fixed in 2.1+dfsg-1)
sid: resolved (fixed in 2.1+dfsg-1)
trixie: resolved (fi
debian
CVE-2019-12155P3HIGHCVSS 7.5fixed in qemu 1:3.1+dfsg-8 (bookworm)2019
CVE-2019-12155 [HIGH] CVE-2019-12155: qemu - interface_release_resource in hw/display/qxl.c in QEMU 3.1.x through 4.0.0 has a...
interface_release_resource in hw/display/qxl.c in QEMU 3.1.x through 4.0.0 has a NULL pointer dereference.
Scope: local
bookworm: resolved (fixed in 1:3.1+dfsg-8)
bullseye: resolved (fixed in 1:3.1+dfsg-8)
forky: resolved (fixed in 1:3.1+dfsg-8)
sid: resolved (fixed in 1:3.1+dfsg-8)
trixie: resolved (fixed in 1:3.1+dfsg-8)
debian
CVE-2018-17963P3CRITICALCVSS 9.8fixed in qemu 1:3.1+dfsg-1 (bookworm)2018
CVE-2018-17963 [CRITICAL] CVE-2018-17963: qemu - qemu_deliver_packet_iov in net/net.c in Qemu accepts packet sizes greater than I...
qemu_deliver_packet_iov in net/net.c in Qemu accepts packet sizes greater than INT_MAX, which allows attackers to cause a denial of service or possibly have unspecified other impact.
Scope: local
bookworm: resolved (fixed in 1:3.1+dfsg-1)
bullseye: resolved (fixed in 1:3.1+dfsg-1)
forky: resolved (fixed in 1:3.1+dfsg-1)
sid: resolved (fixed in 1:3.1+dfsg-1)
trixie:
debian
CVE-2017-15268P3HIGHCVSS 7.5fixed in qemu 1:2.11+dfsg-1 (bookworm)2017
CVE-2017-15268 [HIGH] CVE-2017-15268: qemu - Qemu through 2.10.0 allows remote attackers to cause a memory leak by triggering...
Qemu through 2.10.0 allows remote attackers to cause a memory leak by triggering slow data-channel read operations, related to io/channel-websock.c.
Scope: local
bookworm: resolved (fixed in 1:2.11+dfsg-1)
bullseye: resolved (fixed in 1:2.11+dfsg-1)
forky: resolved (fixed in 1:2.11+dfsg-1)
sid: resolved (fixed in 1:2.11+dfsg-1)
trixie: resolved (fixed in 1:2.11+dfsg-1)
debian
CVE-2013-4526P3LOWCVSS 7.5fixed in qemu 2.1+dfsg-1 (bookworm)2013
CVE-2013-4526 [HIGH] CVE-2013-4526: qemu - Buffer overflow in hw/ide/ahci.c in QEMU before 1.7.2 allows remote attackers to...
Buffer overflow in hw/ide/ahci.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via vectors related to migrating ports.
Scope: local
bookworm: resolved (fixed in 2.1+dfsg-1)
bullseye: resolved (fixed in 2.1+dfsg-1)
forky: resolved (fixed in 2.1+dfsg-1)
sid: resolved (fixed in 2.1+dfsg-1)
trixie: resolved (fix
debian
CVE-2013-4531P3LOWCVSS 7.5fixed in qemu 2.1+dfsg-1 (bookworm)2013
CVE-2013-4531 [HIGH] CVE-2013-4531: qemu - Buffer overflow in target-arm/machine.c in QEMU before 1.7.2 allows remote attac...
Buffer overflow in target-arm/machine.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a negative value in cpreg_vmstate_array_len in a savevm image.
Scope: local
bookworm: resolved (fixed in 2.1+dfsg-1)
bullseye: resolved (fixed in 2.1+dfsg-1)
forky: resolved (fixed in 2.1+dfsg-1)
sid: resolved (fixed in
debian
CVE-2013-4533P3LOWCVSS 7.5fixed in qemu 2.1+dfsg-1 (bookworm)2013
CVE-2013-4533 [HIGH] CVE-2013-4533: qemu - Buffer overflow in the pxa2xx_ssp_load function in hw/arm/pxa2xx.c in QEMU befor...
Buffer overflow in the pxa2xx_ssp_load function in hw/arm/pxa2xx.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service or possibly execute arbitrary code via a crafted s->rx_level value in a savevm image.
Scope: local
bookworm: resolved (fixed in 2.1+dfsg-1)
bullseye: resolved (fixed in 2.1+dfsg-1)
forky: resolved (fixed in 2.1+dfsg-1)
sid: resolved
debian
CVE-2017-9524P3HIGHCVSS 7.5fixed in qemu 1:2.8+dfsg-7 (bookworm)2017
CVE-2017-9524 [HIGH] CVE-2017-9524: qemu - The qemu-nbd server in QEMU (aka Quick Emulator), when built with the Network Bl...
The qemu-nbd server in QEMU (aka Quick Emulator), when built with the Network Block Device (NBD) Server support, allows remote attackers to cause a denial of service (segmentation fault and server crash) by leveraging failure to ensure that all initialization occurs before talking to a client in the nbd_negotiate function.
Scope: local
bookworm: resolved (fixed in 1:2.8+
debian
CVE-2013-4529P3LOWCVSS 7.5fixed in qemu 2.1+dfsg-1 (bookworm)2013
CVE-2013-4529 [HIGH] CVE-2013-4529: qemu - Buffer overflow in hw/pci/pcie_aer.c in QEMU before 1.7.2 allows remote attacker...
Buffer overflow in hw/pci/pcie_aer.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large log_num value in a savevm image.
Scope: local
bookworm: resolved (fixed in 2.1+dfsg-1)
bullseye: resolved (fixed in 2.1+dfsg-1)
forky: resolved (fixed in 2.1+dfsg-1)
sid: resolved (fixed in 2.1+dfsg-1)
trixie: reso
debian
CVE-2022-26353P3HIGHCVSS 7.5fixed in qemu 1:7.0+dfsg-1 (bookworm)2022
CVE-2022-26353 [HIGH] CVE-2022-26353: qemu - A flaw was found in the virtio-net device of QEMU. This flaw was inadvertently i...
A flaw was found in the virtio-net device of QEMU. This flaw was inadvertently introduced with the fix for CVE-2021-3748, which forgot to unmap the cached virtqueue elements on error, leading to memory leakage and other unexpected results. Affected QEMU version: 6.2.0.
Scope: local
bookworm: resolved (fixed in 1:7.0+dfsg-1)
bullseye: resolved (fixed in 1:5.2+dfsg-11+de
debian
CVE-2020-35517P3HIGHCVSS 8.2fixed in qemu 1:5.2+dfsg-5 (bookworm)2020
CVE-2020-35517 [HIGH] CVE-2020-35517: qemu - A flaw was found in qemu. A host privilege escalation issue was found in the vir...
A flaw was found in qemu. A host privilege escalation issue was found in the virtio-fs shared file system daemon where a privileged guest user is able to create a device special file in the shared directory and use it to r/w access host devices.
Scope: local
bookworm: resolved (fixed in 1:5.2+dfsg-5)
bullseye: resolved (fixed in 1:5.2+dfsg-5)
forky: resolved (fixed in
debian
CVE-2021-3546P3HIGHCVSS 8.2fixed in qemu 1:6.1+dfsg-1 (bookworm)2021
CVE-2021-3546 [HIGH] CVE-2021-3546: qemu - An out-of-bounds write vulnerability was found in the virtio vhost-user GPU devi...
An out-of-bounds write vulnerability was found in the virtio vhost-user GPU device (vhost-user-gpu) of QEMU in versions up to and including 6.0. The flaw occurs while processing the 'VIRTIO_GPU_CMD_GET_CAPSET' command from the guest. It could allow a privileged guest user to crash the QEMU process on the host, resulting in a denial of service condition, or potential code
debian
CVE-2016-5126P3HIGHCVSS 7.8fixed in qemu 1:2.6+dfsg-2 (bookworm)2016
CVE-2016-5126 [HIGH] CVE-2016-5126: qemu - Heap-based buffer overflow in the iscsi_aio_ioctl function in block/iscsi.c in Q...
Heap-based buffer overflow in the iscsi_aio_ioctl function in block/iscsi.c in QEMU allows local guest OS users to cause a denial of service (QEMU process crash) or possibly execute arbitrary code via a crafted iSCSI asynchronous I/O ioctl call.
Scope: local
bookworm: resolved (fixed in 1:2.6+dfsg-2)
bullseye: resolved (fixed in 1:2.6+dfsg-2)
forky: resolved (fixed in 1:
debian
CVE-2019-13164P3HIGHCVSS 7.8fixed in qemu 1:4.1-1 (bookworm)2019
CVE-2019-13164 [HIGH] CVE-2019-13164: qemu - qemu-bridge-helper.c in QEMU 3.1 and 4.0.0 does not ensure that a network interf...
qemu-bridge-helper.c in QEMU 3.1 and 4.0.0 does not ensure that a network interface name (obtained from bridge.conf or a --br=bridge option) is limited to the IFNAMSIZ size, which can lead to an ACL bypass.
Scope: local
bookworm: resolved (fixed in 1:4.1-1)
bullseye: resolved (fixed in 1:4.1-1)
forky: resolved (fixed in 1:4.1-1)
sid: resolved (fixed in 1:4.1-1)
trixie:
debian
CVE-2021-3713P3HIGHCVSS 7.4fixed in qemu 1:6.1+dfsg-2 (bookworm)2021
CVE-2021-3713 [HIGH] CVE-2021-3713: qemu - An out-of-bounds write flaw was found in the UAS (USB Attached SCSI) device emul...
An out-of-bounds write flaw was found in the UAS (USB Attached SCSI) device emulation of QEMU in versions prior to 6.2.0-rc0. The device uses the guest supplied stream number unchecked, which can lead to out-of-bounds access to the UASDevice->data3 and UASDevice->status3 fields. A malicious guest user could use this flaw to crash QEMU or potentially achieve code executio
debian
CVE-2020-7039P3MEDIUMCVSS 5.6fixed in libslirp 4.1.0-2 (bookworm)2020
CVE-2020-7039 [MEDIUM] CVE-2020-7039: libslirp - tcp_emu in tcp_subr.c in libslirp 4.1.0, as used in QEMU 4.2.0, mismanages memor...
tcp_emu in tcp_subr.c in libslirp 4.1.0, as used in QEMU 4.2.0, mismanages memory, as demonstrated by IRC DCC commands in EMU_IRC. This can cause a heap-based buffer overflow or other out-of-bounds access which can lead to a DoS or potential execute arbitrary code.
Scope: local
bookworm: resolved (fixed in 4.1.0-2)
bullseye: resolved (fixed in 4.1.0-2)
forky: resol
debian
CVE-2017-10664P3HIGHCVSS 7.5fixed in qemu 1:2.8+dfsg-7 (bookworm)2017
CVE-2017-10664 [HIGH] CVE-2017-10664: qemu - qemu-nbd in QEMU (aka Quick Emulator) does not ignore SIGPIPE, which allows remo...
qemu-nbd in QEMU (aka Quick Emulator) does not ignore SIGPIPE, which allows remote attackers to cause a denial of service (daemon crash) by disconnecting during a server-to-client reply attempt.
Scope: local
bookworm: resolved (fixed in 1:2.8+dfsg-7)
bullseye: resolved (fixed in 1:2.8+dfsg-7)
forky: resolved (fixed in 1:2.8+dfsg-7)
sid: resolved (fixed in 1:2.8+dfsg-7)
debian
CVE-2019-15890P3HIGHCVSS 7.5fixed in qemu 1:4.1-2 (bookworm)2019
CVE-2019-15890 [HIGH] CVE-2019-15890: qemu - libslirp 4.0.0, as used in QEMU 4.1.0, has a use-after-free in ip_reass in ip_in...
libslirp 4.0.0, as used in QEMU 4.1.0, has a use-after-free in ip_reass in ip_input.c.
Scope: local
bookworm: resolved (fixed in 1:4.1-2)
bullseye: resolved (fixed in 1:4.1-2)
forky: resolved (fixed in 1:4.1-2)
sid: resolved (fixed in 1:4.1-2)
trixie: resolved (fixed in 1:4.1-2)
debian
CVE-2015-6855P3HIGHCVSS 7.5fixed in qemu 1:2.4+dfsg-2 (bookworm)2015
CVE-2015-6855 [HIGH] CVE-2015-6855: qemu - hw/ide/core.c in QEMU does not properly restrict the commands accepted by an ATA...
hw/ide/core.c in QEMU does not properly restrict the commands accepted by an ATAPI device, which allows guest users to cause a denial of service or possibly have unspecified other impact via certain IDE commands, as demonstrated by a WIN_READ_NATIVE_MAX command to an empty drive, which triggers a divide-by-zero error and instance crash.
Scope: local
bookworm: resolved (f
debian