📦 Qemu

by Qemu

🔍 What is Qemu?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2022-36648

CRITICAL CVSS 10.0 Aug 22, 2023

This CVE describes a vulnerability in QEMU's hardware emulation where a malformed program executed in a guest OS could crash the host QEMU process and potentially allow code execution on the host. It ...

CVE-2024-7730

HIGH CVSS 7.4 Nov 14, 2024

A heap buffer overflow vulnerability in QEMU's virtio-snd device allows attackers to write beyond allocated memory boundaries when processing audio input. This affects systems running QEMU with virtio...

CVE-2024-6519

HIGH CVSS 8.2 Oct 21, 2024

A use-after-free vulnerability in QEMU's LSI53C895A SCSI Host Bus Adapter emulation allows attackers to cause a denial of service or potentially escape the virtual machine. This affects any system run...

CVE-2024-24474

HIGH CVSS 8.8 Feb 20, 2024

This CVE describes an integer underflow and buffer overflow vulnerability in QEMU's SCSI emulation (esp.c). Attackers can exploit this to execute arbitrary code or cause denial-of-service on the QEMU ...

CVE-2023-2680

HIGH CVSS 7.5 Sep 13, 2023

CVE-2023-2680 is a use-after-free vulnerability in qemu-kvm virtualization software that occurs due to an incomplete fix for CVE-2021-3750. This allows attackers with guest VM access to potentially ex...

CVE-2023-0664

HIGH CVSS 7.8 Mar 29, 2023

This vulnerability allows a local unprivileged user on Windows systems running QEMU Guest Agent to manipulate the installer's repair custom actions, leading to privilege escalation. Attackers can gain...

CVE-2022-35414

HIGH CVSS 8.8 Jul 11, 2022

CVE-2022-35414 is an uninitialized read vulnerability in QEMU's memory management component that can lead to crashes when handling I/O operations. This affects QEMU versions through 7.0.0 when used in...

CVE-2021-3750

HIGH CVSS 8.2 May 2, 2022

A DMA reentrancy vulnerability in QEMU's USB EHCI controller emulation allows malicious guests to write crafted data to controller registers during packet transfers. This can trigger use-after-free co...

CVE-2021-4206

HIGH CVSS 8.2 Apr 29, 2022

This vulnerability in QEMU's QXL display device emulation allows a malicious privileged guest user to trigger an integer overflow and subsequent heap buffer overflow. This can crash the QEMU process o...

CVE-2022-26353

HIGH CVSS 7.5 Mar 16, 2022

A memory leak vulnerability in QEMU's virtio-net device occurs when cached virtqueue elements aren't unmapped during error conditions. This flaw affects QEMU version 6.2.0 and can lead to memory exhau...

CVE-2021-3713

HIGH CVSS 7.4 Aug 25, 2021

This vulnerability allows a malicious guest user in QEMU virtual machines to perform out-of-bounds writes in the UAS device emulation, potentially leading to QEMU process crashes or arbitrary code exe...

CVE-2021-3682

HIGH CVSS 8.5 Aug 5, 2021

This vulnerability in QEMU's USB redirector device emulation allows a malicious SPICE client to trigger a heap corruption when packet queues fill during bulk transfers. Successful exploitation could l...

CVE-2021-3546

HIGH CVSS 8.2 Jun 2, 2021

This vulnerability allows a privileged guest user in QEMU virtual machines to trigger an out-of-bounds write in the virtio vhost-user GPU device. It can crash the QEMU process on the host (denial of s...

CVE-2025-54567

MEDIUM CVSS 4.2 Jul 25, 2025

This vulnerability in QEMU's PCIe Single Root I/O Virtualization (SR-IOV) implementation allows attackers with guest VM access to potentially manipulate Virtual Function (VF) enable bits incorrectly. ...

CVE-2024-8354

MEDIUM CVSS 5.5 Sep 19, 2024

A vulnerability in QEMU's USB endpoint handling allows unprivileged guest users to trigger an assertion failure, crashing the QEMU process on the host. This causes a denial of service affecting any ho...

CVE-2024-6505

MEDIUM CVSS 6.8 Jul 5, 2024

A heap overflow vulnerability in QEMU's virtio-net device allows privileged guest users to crash the host QEMU process by manipulating RSS indirections_table values. This affects virtualization enviro...

CVE-2023-1544

MEDIUM CVSS 6.0 Mar 23, 2023

This vulnerability in QEMU's VMWare paravirtual RDMA device allows a malicious guest VM driver to allocate excessive page tables, potentially causing an out-of-bounds read and QEMU crash. It affects s...