cbcvebase.

Debian Qemu vulnerabilities

424 known vulnerabilities affecting debian/qemu.

Total CVEs
424
CISA KEV
0
Public exploits
7
Exploited in wild
0
Severity breakdown
CRITICAL10HIGH85MEDIUM226LOW102UNKNOWN1

Vulnerabilities

Page 6 of 22
CVE-2015-8550P3HIGHCVSS 8.2fixed in linux 4.3.3-3 (bookworm)2015
CVE-2015-8550 [HIGH] CVE-2015-8550: linux - Xen, when used on a system providing PV backends, allows local guest OS administ... Xen, when used on a system providing PV backends, allows local guest OS administrators to cause a denial of service (host OS crash) or gain privileges by writing to memory shared between the frontend and backend, aka a double fetch vulnerability. Scope: local bookworm: resolved (fixed in 4.3.3-3) bullseye: resolved (fixed in 4.3.3-3) forky: resolved (fixed in 4.3.3-3) s
debian
CVE-2018-11806P3HIGHCVSS 8.2fixed in qemu 1:3.1+dfsg-1 (bookworm)2018
CVE-2018-11806 [HIGH] CVE-2018-11806: qemu - m_cat in slirp/mbuf.c in Qemu has a heap-based buffer overflow via incoming frag... m_cat in slirp/mbuf.c in Qemu has a heap-based buffer overflow via incoming fragmented datagrams. Scope: local bookworm: resolved (fixed in 1:3.1+dfsg-1) bullseye: resolved (fixed in 1:3.1+dfsg-1) forky: resolved (fixed in 1:3.1+dfsg-1) sid: resolved (fixed in 1:3.1+dfsg-1) trixie: resolved (fixed in 1:3.1+dfsg-1)
debian
CVE-2021-3748P3HIGHCVSS 7.5fixed in qemu 1:6.1+dfsg-6 (bookworm)2021
CVE-2021-3748 [HIGH] CVE-2021-3748: qemu - A use-after-free vulnerability was found in the virtio-net device of QEMU. It co... A use-after-free vulnerability was found in the virtio-net device of QEMU. It could occur when the descriptor's address belongs to the non direct access region, due to num_buffers being set after the virtqueue elem has been unmapped. A malicious guest could use this flaw to crash QEMU, resulting in a denial of service condition, or potentially execute code on the host wi
debian
CVE-2015-8619P3HIGHCVSS 7.5fixed in qemu 1:2.5+dfsg-5 (bookworm)2015
CVE-2015-8619 [HIGH] CVE-2015-8619: qemu - The Human Monitor Interface support in QEMU allows remote attackers to cause a d... The Human Monitor Interface support in QEMU allows remote attackers to cause a denial of service (out-of-bounds write and application crash). Scope: local bookworm: resolved (fixed in 1:2.5+dfsg-5) bullseye: resolved (fixed in 1:2.5+dfsg-5) forky: resolved (fixed in 1:2.5+dfsg-5) sid: resolved (fixed in 1:2.5+dfsg-5) trixie: resolved (fixed in 1:2.5+dfsg-5)
debian
CVE-2018-20216P3LOWCVSS 7.5fixed in qemu 1:4.1-1 (bookworm)2018
CVE-2018-20216 [HIGH] CVE-2018-20216: qemu - QEMU can have an infinite loop in hw/rdma/vmw/pvrdma_dev_ring.c because return v... QEMU can have an infinite loop in hw/rdma/vmw/pvrdma_dev_ring.c because return values are not checked (and -1 is mishandled). Scope: local bookworm: resolved (fixed in 1:4.1-1) bullseye: resolved (fixed in 1:4.1-1) forky: resolved (fixed in 1:4.1-1) sid: resolved (fixed in 1:4.1-1) trixie: resolved (fixed in 1:4.1-1)
debian
CVE-2017-13711P3HIGHCVSS 7.5fixed in qemu 1:2.10.0-1 (bookworm)2017
CVE-2017-13711 [HIGH] CVE-2017-13711: qemu - Use-after-free vulnerability in the sofree function in slirp/socket.c in QEMU (a... Use-after-free vulnerability in the sofree function in slirp/socket.c in QEMU (aka Quick Emulator) allows attackers to cause a denial of service (QEMU instance crash) by leveraging failure to properly clear ifq_so from pending packets. Scope: local bookworm: resolved (fixed in 1:2.10.0-1) bullseye: resolved (fixed in 1:2.10.0-1) forky: resolved (fixed in 1:2.10.0-1) si
debian
CVE-2017-7980P3HIGHCVSS 7.8fixed in qemu 1:2.8+dfsg-4 (bookworm)2017
CVE-2017-7980 [HIGH] CVE-2017-7980: qemu - Heap-based buffer overflow in Cirrus CLGD 54xx VGA Emulator in Quick Emulator (Q... Heap-based buffer overflow in Cirrus CLGD 54xx VGA Emulator in Quick Emulator (Qemu) 2.8 and earlier allows local guest OS users to execute arbitrary code or cause a denial of service (crash) via vectors related to a VNC client updating its display after a VGA operation. Scope: local bookworm: resolved (fixed in 1:2.8+dfsg-4) bullseye: resolved (fixed in 1:2.8+dfsg-4) fo
debian
CVE-2017-7493P3HIGHCVSS 7.8fixed in qemu 1:2.8+dfsg-6 (bookworm)2017
CVE-2017-7493 [HIGH] CVE-2017-7493: qemu - Quick Emulator (Qemu) built with the VirtFS, host directory sharing via Plan 9 F... Quick Emulator (Qemu) built with the VirtFS, host directory sharing via Plan 9 File System(9pfs) support, is vulnerable to an improper access control issue. It could occur while accessing virtfs metadata files in mapped-file security mode. A guest user could use this flaw to escalate their privileges inside guest. Scope: local bookworm: resolved (fixed in 1:2.8+dfsg-6) b
debian
CVE-2021-20181P3HIGHCVSS 7.5fixed in qemu 1:5.2+dfsg-4 (bookworm)2021
CVE-2021-20181 [HIGH] CVE-2021-20181: qemu - A race condition flaw was found in the 9pfs server implementation of QEMU up to ... A race condition flaw was found in the 9pfs server implementation of QEMU up to and including 5.2.0. This flaw allows a malicious 9p client to cause a use-after-free error, potentially escalating their privileges on the system. The highest threat from this vulnerability is to confidentiality, integrity as well as system availability. Scope: local bookworm: resolved (fi
debian
CVE-2015-8567P3HIGHCVSS 7.7fixed in qemu 1:2.5+dfsg-3 (bookworm)2015
CVE-2015-8567 [HIGH] CVE-2015-8567: qemu - Memory leak in net/vmxnet3.c in QEMU allows remote attackers to cause a denial o... Memory leak in net/vmxnet3.c in QEMU allows remote attackers to cause a denial of service (memory consumption). Scope: local bookworm: resolved (fixed in 1:2.5+dfsg-3) bullseye: resolved (fixed in 1:2.5+dfsg-3) forky: resolved (fixed in 1:2.5+dfsg-3) sid: resolved (fixed in 1:2.5+dfsg-3) trixie: resolved (fixed in 1:2.5+dfsg-3)
debian
CVE-2026-3195P3LOWfixed in qemu 1:10.2.2+ds-1 (forky)2026
CVE-2026-3195 [LOW] CVE-2026-3195: qemu bookworm: resolved bullseye: resolved forky: resolved (fixed in 1:10.2.2+ds-1) sid: resolved (fixed in 1:10.2.2+ds-1) trixie: open
debian
CVE-2019-5008P3LOWCVSS 7.5fixed in qemu 1:3.1+dfsg-8 (bookworm)2019
CVE-2019-5008 [HIGH] CVE-2019-5008: qemu - hw/sparc64/sun4u.c in QEMU 3.1.50 is vulnerable to a NULL pointer dereference, w... hw/sparc64/sun4u.c in QEMU 3.1.50 is vulnerable to a NULL pointer dereference, which allows the attacker to cause a denial of service via a device driver. Scope: local bookworm: resolved (fixed in 1:3.1+dfsg-8) bullseye: resolved (fixed in 1:3.1+dfsg-8) forky: resolved (fixed in 1:3.1+dfsg-8) sid: resolved (fixed in 1:3.1+dfsg-8) trixie: resolved (fixed in 1:3.1+dfsg-8)
debian
CVE-2014-0145P3HIGHCVSS 7.8fixed in qemu 2.0.0+dfsg-1 (bookworm)2014
CVE-2014-0145 [HIGH] CVE-2014-0145: qemu - Multiple buffer overflows in QEMU before 1.7.2 and 2.x before 2.0.0, allow local... Multiple buffer overflows in QEMU before 1.7.2 and 2.x before 2.0.0, allow local users to cause a denial of service (crash) or possibly execute arbitrary code via a large (1) L1 table in the qcow2_snapshot_load_tmp in the QCOW 2 block driver (block/qcow2-snapshot.c) or (2) uncompressed chunk, (3) chunk length, or (4) number of sectors in the DMG block driver (block/dmg.c
debian
CVE-2016-5338P3HIGHCVSS 7.8fixed in qemu 1:2.6+dfsg-2 (bookworm)2016
CVE-2016-5338 [HIGH] CVE-2016-5338: qemu - The (1) esp_reg_read and (2) esp_reg_write functions in hw/scsi/esp.c in QEMU al... The (1) esp_reg_read and (2) esp_reg_write functions in hw/scsi/esp.c in QEMU allow local guest OS administrators to cause a denial of service (QEMU process crash) or execute arbitrary code on the QEMU host via vectors related to the information transfer buffer. Scope: local bookworm: resolved (fixed in 1:2.6+dfsg-2) bullseye: resolved (fixed in 1:2.6+dfsg-2) forky: reso
debian
CVE-2023-3255P3MEDIUMCVSS 6.5fixed in qemu 1:7.2+dfsg-7+deb12u2 (bookworm)2023
CVE-2023-3255 [MEDIUM] CVE-2023-3255: qemu - A flaw was found in the QEMU built-in VNC server while processing ClientCutText ... A flaw was found in the QEMU built-in VNC server while processing ClientCutText messages. A wrong exit condition may lead to an infinite loop when inflating an attacker controlled zlib buffer in the `inflate_buffer` function. This could allow a remote authenticated client who is able to send a clipboard to the VNC server to trigger a denial of service. Scope: local boo
debian
CVE-2017-8309P4HIGHCVSS 7.5fixed in qemu 1:2.8+dfsg-5 (bookworm)2017
CVE-2017-8309 [HIGH] CVE-2017-8309: qemu - Memory leak in the audio/audio.c in QEMU (aka Quick Emulator) allows remote atta... Memory leak in the audio/audio.c in QEMU (aka Quick Emulator) allows remote attackers to cause a denial of service (memory consumption) by repeatedly starting and stopping audio capture. Scope: local bookworm: resolved (fixed in 1:2.8+dfsg-5) bullseye: resolved (fixed in 1:2.8+dfsg-5) forky: resolved (fixed in 1:2.8+dfsg-5) sid: resolved (fixed in 1:2.8+dfsg-5) trixie: r
debian
CVE-2015-4104P3HIGHCVSS 7.8fixed in qemu 1:2.3+dfsg-5 (bookworm)2015
CVE-2015-4104 [HIGH] CVE-2015-4104: qemu - Xen 3.3.x through 4.5.x does not properly restrict access to PCI MSI mask bits, ... Xen 3.3.x through 4.5.x does not properly restrict access to PCI MSI mask bits, which allows local x86 HVM guest users to cause a denial of service (unexpected interrupt and host crash) via unspecified vectors. Scope: local bookworm: resolved (fixed in 1:2.3+dfsg-5) bullseye: resolved (fixed in 1:2.3+dfsg-5) forky: resolved (fixed in 1:2.3+dfsg-5) sid: resolved (fixed in
debian
CVE-2018-20125P4LOWCVSS 7.5fixed in qemu 1:4.1-1 (bookworm)2018
CVE-2018-20125 [HIGH] CVE-2018-20125: qemu - hw/rdma/vmw/pvrdma_cmd.c in QEMU allows attackers to cause a denial of service (... hw/rdma/vmw/pvrdma_cmd.c in QEMU allows attackers to cause a denial of service (NULL pointer dereference or excessive memory allocation) in create_cq_ring or create_qp_rings. Scope: local bookworm: resolved (fixed in 1:4.1-1) bullseye: resolved (fixed in 1:4.1-1) forky: resolved (fixed in 1:4.1-1) sid: resolved (fixed in 1:4.1-1) trixie: resolved (fixed in 1:4.1-1)
debian
CVE-2023-5088P3MEDIUMCVSS 6.4fixed in qemu 1:7.2+dfsg-7+deb12u3 (bookworm)2023
CVE-2023-5088 [MEDIUM] CVE-2023-5088: qemu - A bug in QEMU could cause a guest I/O operation otherwise addressed to an arbitr... A bug in QEMU could cause a guest I/O operation otherwise addressed to an arbitrary disk offset to be targeted to offset 0 instead (potentially overwriting the VM's boot code). This could be used, for example, by L2 guests with a virtual disk (vdiskL2) stored on a virtual disk of an L1 (vdiskL1) hypervisor to read and/or write data to LBA 0 of vdiskL1, potentially gain
debian
CVE-2008-5714P4LOWCVSS 7.8fixed in qemu 0.9.1-10 (bookworm)2008
CVE-2008-5714 [HIGH] CVE-2008-5714: qemu - Off-by-one error in monitor.c in Qemu 0.9.1 might make it easier for remote atta... Off-by-one error in monitor.c in Qemu 0.9.1 might make it easier for remote attackers to guess the VNC password, which is limited to seven characters where eight was intended. Scope: local bookworm: resolved (fixed in 0.9.1-10) bullseye: resolved (fixed in 0.9.1-10) forky: resolved (fixed in 0.9.1-10) sid: resolved (fixed in 0.9.1-10) trixie: resolved (fixed in 0.9.1-10)
debian
Debian Qemu vulnerabilities | cvebase