Debian Qemu vulnerabilities
424 known vulnerabilities affecting debian/qemu.
Total CVEs
424
CISA KEV
0
Public exploits
7
Exploited in wild
0
Severity breakdown
CRITICAL10HIGH85MEDIUM226LOW102UNKNOWN1
Vulnerabilities
Page 9 of 22
CVE-2017-8284P4LOWCVSS 7.0fixed in qemu 1:2.10.0-1 (bookworm)2017
CVE-2017-8284 [HIGH] CVE-2017-8284: qemu - The disas_insn function in target/i386/translate.c in QEMU before 2.9.0, when TC...
The disas_insn function in target/i386/translate.c in QEMU before 2.9.0, when TCG mode without hardware acceleration is used, does not limit the instruction size, which allows local users to gain privileges by creating a modified basic block that injects code into a setuid program, as demonstrated by procmail. NOTE: the vendor has stated "this bug does not violate any se
debian
CVE-2015-7295P4MEDIUMCVSS 5.0fixed in qemu 1:2.4+dfsg-4 (bookworm)2015
CVE-2015-7295 [MEDIUM] CVE-2015-7295: qemu - hw/virtio/virtio.c in the Virtual Network Device (virtio-net) support in QEMU, w...
hw/virtio/virtio.c in the Virtual Network Device (virtio-net) support in QEMU, when big or mergeable receive buffers are not supported, allows remote attackers to cause a denial of service (guest network consumption) via a flood of jumbo frames on the (1) tuntap or (2) macvtap interface.
Scope: local
bookworm: resolved (fixed in 1:2.4+dfsg-4)
bullseye: resolved (fixed
debian
CVE-2020-13754P4MEDIUMCVSS 6.7fixed in qemu 1:5.0-6 (bookworm)2020
CVE-2020-13754 [MEDIUM] CVE-2020-13754: qemu - hw/pci/msix.c in QEMU 4.2.0 allows guest OS users to trigger an out-of-bounds ac...
hw/pci/msix.c in QEMU 4.2.0 allows guest OS users to trigger an out-of-bounds access via a crafted address in an msi-x mmio operation.
Scope: local
bookworm: resolved (fixed in 1:5.0-6)
bullseye: resolved (fixed in 1:5.0-6)
forky: resolved (fixed in 1:5.0-6)
sid: resolved (fixed in 1:5.0-6)
trixie: resolved (fixed in 1:5.0-6)
debian
CVE-2020-10756P4MEDIUMCVSS 6.5fixed in libslirp 4.3.1-1 (bookworm)2020
CVE-2020-10756 [MEDIUM] CVE-2020-10756: libslirp - An out-of-bounds read vulnerability was found in the SLiRP networking implementa...
An out-of-bounds read vulnerability was found in the SLiRP networking implementation of the QEMU emulator. This flaw occurs in the icmp6_send_echoreply() routine while replying to an ICMP echo request, also known as ping. This flaw allows a malicious guest to leak the contents of the host memory, resulting in possible information disclosure. This flaw affects ver
debian
CVE-2021-3545P4MEDIUMCVSS 6.5fixed in qemu 1:6.1+dfsg-1 (bookworm)2021
CVE-2021-3545 [MEDIUM] CVE-2021-3545: qemu - An information disclosure vulnerability was found in the virtio vhost-user GPU d...
An information disclosure vulnerability was found in the virtio vhost-user GPU device (vhost-user-gpu) of QEMU in versions up to and including 6.0. The flaw exists in virgl_cmd_get_capset_info() in contrib/vhost-user-gpu/virgl.c and could occur due to the read of uninitialized memory. A malicious guest could exploit this issue to leak memory from the host.
Scope: local
debian
CVE-2021-3507P4MEDIUMCVSS 6.1fixed in qemu 1:7.1+dfsg-1 (bookworm)2021
CVE-2021-3507 [MEDIUM] CVE-2021-3507: qemu - A heap buffer overflow was found in the floppy disk emulator of QEMU up to 6.0.0...
A heap buffer overflow was found in the floppy disk emulator of QEMU up to 6.0.0 (including). It could occur in fdctrl_transfer_handler() in hw/block/fdc.c while processing DMA read data transfers from the floppy drive to the guest system. A privileged guest user could use this flaw to crash the QEMU process on the host resulting in DoS scenario, or potential informati
debian
CVE-2020-1983P4HIGHCVSS 7.5fixed in libslirp 4.2.0-2 (bookworm)2020
CVE-2020-1983 [HIGH] CVE-2020-1983: libslirp - A use after free vulnerability in ip_reass() in ip_input.c of libslirp 4.2.0 and...
A use after free vulnerability in ip_reass() in ip_input.c of libslirp 4.2.0 and prior releases allows crafted packets to cause a denial of service.
Scope: local
bookworm: resolved (fixed in 4.2.0-2)
bullseye: resolved (fixed in 4.2.0-2)
forky: resolved (fixed in 4.2.0-2)
sid: resolved (fixed in 4.2.0-2)
trixie: resolved (fixed in 4.2.0-2)
debian
CVE-2020-10761P4MEDIUMCVSS 5.0fixed in qemu 1:5.0-6 (bookworm)2020
CVE-2020-10761 [MEDIUM] CVE-2020-10761: qemu - An assertion failure issue was found in the Network Block Device(NBD) Server in ...
An assertion failure issue was found in the Network Block Device(NBD) Server in all QEMU versions before QEMU 5.0.1. This flaw occurs when an nbd-client sends a spec-compliant request that is near the boundary of maximum permitted request length. A remote nbd-client could use this flaw to crash the qemu-nbd server resulting in a denial of service.
Scope: local
bookwo
debian
CVE-2015-8504P4MEDIUMCVSS 6.5fixed in qemu 1:2.5+dfsg-1 (bookworm)2015
CVE-2015-8504 [MEDIUM] CVE-2015-8504: qemu - Qemu, when built with VNC display driver support, allows remote attackers to cau...
Qemu, when built with VNC display driver support, allows remote attackers to cause a denial of service (arithmetic exception and application crash) via crafted SetPixelFormat messages from a client.
Scope: local
bookworm: resolved (fixed in 1:2.5+dfsg-1)
bullseye: resolved (fixed in 1:2.5+dfsg-1)
forky: resolved (fixed in 1:2.5+dfsg-1)
sid: resolved (fixed in 1:2.5+dfs
debian
CVE-2023-6693P4MEDIUMCVSS 4.9fixed in qemu 1:7.2+dfsg-7+deb12u4 (bookworm)2023
CVE-2023-6693 [MEDIUM] CVE-2023-6693: qemu - A stack based buffer overflow was found in the virtio-net device of QEMU. This i...
A stack based buffer overflow was found in the virtio-net device of QEMU. This issue occurs when flushing TX in the virtio_net_flush_tx function if guest features VIRTIO_NET_F_HASH_REPORT, VIRTIO_F_VERSION_1 and VIRTIO_NET_F_MRG_RXBUF are enabled. This could allow a malicious user to overwrite local variables allocated on the stack. Specifically, the `out_sg` variable
debian
CVE-2014-3689P4HIGHCVSS 7.2fixed in qemu 2.1+dfsg-6 (bookworm)2014
CVE-2014-3689 [HIGH] CVE-2014-3689: qemu - The vmware-vga driver (hw/display/vmware_vga.c) in QEMU allows local guest users...
The vmware-vga driver (hw/display/vmware_vga.c) in QEMU allows local guest users to write to qemu memory locations and gain privileges via unspecified parameters related to rectangle handling.
Scope: local
bookworm: resolved (fixed in 2.1+dfsg-6)
bullseye: resolved (fixed in 2.1+dfsg-6)
forky: resolved (fixed in 2.1+dfsg-6)
sid: resolved (fixed in 2.1+dfsg-6)
trixie: res
debian
CVE-2016-2538P4HIGHCVSS 7.1fixed in qemu 1:2.6+dfsg-1 (bookworm)2016
CVE-2016-2538 [HIGH] CVE-2016-2538: qemu - Multiple integer overflows in the USB Net device emulator (hw/usb/dev-network.c)...
Multiple integer overflows in the USB Net device emulator (hw/usb/dev-network.c) in QEMU before 2.5.1 allow local guest OS administrators to cause a denial of service (QEMU process crash) or obtain sensitive host memory information via a remote NDIS control message packet that is mishandled in the (1) rndis_query_response, (2) rndis_set_response, or (3) usb_net_handle_da
debian
CVE-2014-0143P4HIGHCVSS 7.0fixed in qemu 2.0.0+dfsg-1 (bookworm)2014
CVE-2014-0143 [HIGH] CVE-2014-0143: qemu - Multiple integer overflows in the block drivers in QEMU, possibly before 2.0.0, ...
Multiple integer overflows in the block drivers in QEMU, possibly before 2.0.0, allow local users to cause a denial of service (crash) via a crafted catalog size in (1) the parallels_open function in block/parallels.c or (2) bochs_open function in bochs.c, a large L1 table in the (3) qcow2_snapshot_load_tmp in qcow2-snapshot.c or (4) qcow2_grow_l1_table function in qcow2
debian
CVE-2021-3611P4MEDIUMCVSS 6.5fixed in qemu 1:7.0+dfsg-1 (bookworm)2021
CVE-2021-3611 [MEDIUM] CVE-2021-3611: qemu - A stack overflow vulnerability was found in the Intel HD Audio device (intel-hda...
A stack overflow vulnerability was found in the Intel HD Audio device (intel-hda) of QEMU. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition. The highest threat from this vulnerability is to system availability. This flaw affects QEMU versions prior to 7.0.0.
Scope: local
bookworm: resolved (fixed in
debian
CVE-2017-10911P4MEDIUMCVSS 6.5fixed in linux 4.11.11-1 (bookworm)2017
CVE-2017-10911 [MEDIUM] CVE-2017-10911: linux - The make_response function in drivers/block/xen-blkback/blkback.c in the Linux k...
The make_response function in drivers/block/xen-blkback/blkback.c in the Linux kernel before 4.11.8 allows guest OS users to obtain sensitive information from host OS (or other guest OS) kernel memory by leveraging the copying of uninitialized padding fields in Xen block-interface response structures, aka XSA-216.
Scope: local
bookworm: resolved (fixed in 4.11.11-1)
debian
CVE-2017-5667P4MEDIUMCVSS 6.5fixed in qemu 1:2.8+dfsg-3 (bookworm)2017
CVE-2017-5667 [MEDIUM] CVE-2017-5667: qemu - The sdhci_sdma_transfer_multi_blocks function in hw/sd/sdhci.c in QEMU (aka Quic...
The sdhci_sdma_transfer_multi_blocks function in hw/sd/sdhci.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (out-of-bounds heap access and crash) or execute arbitrary code on the QEMU host via vectors involving the data transfer length.
Scope: local
bookworm: resolved (fixed in 1:2.8+dfsg-3)
bullseye: resolved (fixed
debian
CVE-2025-12464P4LOWCVSS 6.2fixed in qemu 1:10.1.3+ds-1 (forky)2025
CVE-2025-12464 [MEDIUM] CVE-2025-12464: qemu - A stack-based buffer overflow was found in the QEMU e1000 network device. The co...
A stack-based buffer overflow was found in the QEMU e1000 network device. The code for padding short frames was dropped from individual network devices and moved to the net core code. The issue stems from the device's receive code still being able to process a short frame in loopback mode. This could lead to a buffer overrun in the e1000_receive_iov() function via th
debian
CVE-2016-2858P4MEDIUMCVSS 6.5fixed in qemu 1:2.6+dfsg-1 (bookworm)2016
CVE-2016-2858 [MEDIUM] CVE-2016-2858: qemu - QEMU, when built with the Pseudo Random Number Generator (PRNG) back-end support...
QEMU, when built with the Pseudo Random Number Generator (PRNG) back-end support, allows local guest OS users to cause a denial of service (process crash) via an entropy request, which triggers arbitrary stack based allocation and memory corruption.
Scope: local
bookworm: resolved (fixed in 1:2.6+dfsg-1)
bullseye: resolved (fixed in 1:2.6+dfsg-1)
forky: resolved (fixed
debian
CVE-2022-4172P4MEDIUMCVSS 6.5fixed in qemu 1:7.2+dfsg-1 (bookworm)2022
CVE-2022-4172 [MEDIUM] CVE-2022-4172: qemu - An integer overflow and buffer overflow issues were found in the ACPI Error Reco...
An integer overflow and buffer overflow issues were found in the ACPI Error Record Serialization Table (ERST) device of QEMU in the read_erst_record() and write_erst_record() functions. Both issues may allow the guest to overrun the host buffer allocated for the ERST memory device. A malicious guest could use these flaws to crash the QEMU process on the host.
Scope: lo
debian
CVE-2026-0665P4LOWCVSS 6.5fixed in qemu 1:10.2.0+ds-2 (forky)2026
CVE-2026-0665 [MEDIUM] CVE-2026-0665: qemu - An off-by-one error was found in QEMU's KVM Xen guest support. A malicious guest...
An off-by-one error was found in QEMU's KVM Xen guest support. A malicious guest could use this flaw to trigger out-of-bounds heap accesses in the QEMU process via the emulated Xen physdev hypercall interface, leading to a denial of service or potential memory corruption.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 1:10.2.0+ds-2)
sid: r
debian