{"id":"OESA-2026-3845","summary":"qemu security update","details":"QEMU is a FAST! processor emulator using dynamic translation to achieve good emulation speed.\r\n\r\nSecurity Fix(es):\n\nAn unknown vulnerability exists in QEMU, with no detailed description available at this time.(CVE-2026-15264)\n\nCVE-2026-16457 is a security vulnerability in QEMU. The specific details of this vulnerability have not been fully disclosed. This vulnerability may affect the normal operation of the QEMU virtualization platform and poses potential security risks.(CVE-2026-16457)\n\nCVE-2026-18054 is a vulnerability in QEMU, details are not yet disclosed.(CVE-2026-18054)\n\nThis update to qemu-10.2.4-2.mga10 fixes 14 CVEs from 10.2.3 and 2 from\n10.2.4(CVE-2026-3890)\n\nThis update to qemu-10.2.4-2.mga10 fixes 14 CVEs from 10.2.3 and 2 from 10.2.4. This vulnerability (CVE-2026-48004) is one of them.(CVE-2026-48004)\n\nQEMU&amp;#39;s virtio-rng frontend does not cancel or detach an RngRequest that is still pending on the rng-random backend before releasing the VirtIORNG object in virtio_rng_device_unrealize(). When a virtio-rng device is hot-plugged (device_del) and there are still entropy requests pending, the delayed backend completion calls the chr_read callback on the released object, causing the host heap to be use-after-free. An attacker able to trigger hot-plugging of the device could exploit this memory security flaw to compromise the QEMU process, causing a denial of service or potential code execution on the host.(CVE-2026-50624)\n\nAn unknown vulnerability exists in QEMU, details are not yet disclosed.(CVE-2026-50626)\n\nNo detailed vulnerability information available.(CVE-2026-61402)\n\nAn unspecified vulnerability exists in QEMU, with no detailed information available at this time.(CVE-2026-61476)\n\nCVE-2026-63109 is a vulnerability in QEMU. Details of this vulnerability have not been publicly disclosed yet.(CVE-2026-63109)\n\nNo detailed description available.(CVE-2026-63110)\n\nAn unknown vulnerability exists in QEMU, the details of which have not yet been disclosed. Attackers may exploit this vulnerability to cause unknown impacts.(CVE-2026-63320)\n\nAn unknown vulnerability exists in QEMU, the details of which have not yet been disclosed. Attackers may exploit this vulnerability to cause unknown impacts.(CVE-2026-63321)\n\nWhen QEMU&amp;#39;s uefi-vars-x64 virtual device processes the VarCheckPolicy REGISTER command, the uefi_vars_mm_check_policy_register() function directly reads pe-&gt;size without first verifying whether the request length contains the complete variable_policy_entry header. The guest can send a REGISTER request with a length of exactly sizeof(mm_check_policy) (excluding variable_policy_entry), causing the func pointer to cross the end of the allocated MM communication buffer, causing the host heap buffer to read out of bounds (heap-buffer-overflow). An attacker could exploit this memory security flaw to compromise the QEMU process, causing a denial of service or potential code execution on the host.(CVE-2026-63322)\n\nAn undisclosed vulnerability exists in QEMU, the details of which are not yet publicly available.(CVE-2026-63323)\n\nAn unknown type vulnerability exists in QEMU (Quick Emulator). The specific details have not been disclosed yet.(CVE-2026-65928)\n\nCVE-2026-65929 is a security vulnerability affecting QEMU, with no detailed technical information disclosed yet.(CVE-2026-65929)\n\nQEMU (Quick Emulator) is an open-source machine emulator and virtualizer widely used to run operating systems for different architectures. CVE-2026-66021 is a security vulnerability affecting QEMU, with specific details not yet fully disclosed.(CVE-2026-66021)\n\nAn unspecified vulnerability exists in QEMU, the details of which have not been disclosed.(CVE-2026-66022)\n\nQEMU&amp;#39;s VNC extended clipboard handler, after decompressing a client-controlled clipboard payload, compares the declared text size to the entire decompression buffer size, but then copies tsize bytes from buf + 4. The correct boundary is the remaining data length after the 4-byte length field. Therefore, a VNC client can cause QEMU to read up to 3 bytes out of bounds from the end of the decompressed heap buffer; a second VNC client can observe these bytes through the normal VNC extended clipboard PROVIDE path.(CVE-2026-8343)","modified":"2026-09-13T16:45:51.152429033Z","published":"2026-09-14T16:34:55Z","upstream":["CVE-2026-15264","CVE-2026-16457","CVE-2026-18054","CVE-2026-3890","CVE-2026-48004","CVE-2026-50624","CVE-2026-50626","CVE-2026-61402","CVE-2026-61476","CVE-2026-63109","CVE-2026-63110","CVE-2026-63320","CVE-2026-63321","CVE-2026-63322","CVE-2026-63323","CVE-2026-65928","CVE-2026-65929","CVE-2026-66021","CVE-2026-66022","CVE-2026-8343"],"database_specific":{"severity":"High"},"references":[{"type":"ADVISORY","url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3845"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-15264"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-16457"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-18054"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-3890"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48004"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-50624"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-50626"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-61402"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-61476"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-63109"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-63110"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-63320"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-63321"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-63322"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-63323"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-65928"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-65929"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-66021"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-66022"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-8343"}],"affected":[{"package":{"name":"qemu","ecosystem":"openEuler:24.03-LTS-SP4","purl":"pkg:rpm/openEuler/qemu&distro=openEuler-24.03-LTS-SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"8.2.0-86.oe2403sp4"}]}],"ecosystem_specific":{"src":["qemu-8.2.0-86.oe2403sp4.src.rpm"],"x86_64":["qemu-8.2.0-86.oe2403sp4.x86_64.rpm","qemu-block-curl-8.2.0-86.oe2403sp4.x86_64.rpm","qemu-block-iscsi-8.2.0-86.oe2403sp4.x86_64.rpm","qemu-block-rbd-8.2.0-86.oe2403sp4.x86_64.rpm","qemu-block-ssh-8.2.0-86.oe2403sp4.x86_64.rpm","qemu-debuginfo-8.2.0-86.oe2403sp4.x86_64.rpm","qemu-debugsource-8.2.0-86.oe2403sp4.x86_64.rpm","qemu-guest-agent-8.2.0-86.oe2403sp4.x86_64.rpm","qemu-hw-usb-host-8.2.0-86.oe2403sp4.x86_64.rpm","qemu-img-8.2.0-86.oe2403sp4.x86_64.rpm","qemu-seabios-8.2.0-86.oe2403sp4.x86_64.rpm","qemu-system-aarch64-8.2.0-86.oe2403sp4.x86_64.rpm","qemu-system-arm-8.2.0-86.oe2403sp4.x86_64.rpm","qemu-system-riscv-8.2.0-86.oe2403sp4.x86_64.rpm","qemu-system-x86_64-8.2.0-86.oe2403sp4.x86_64.rpm","qemu-user-8.2.0-86.oe2403sp4.x86_64.rpm","qemu-user-binfmt-8.2.0-86.oe2403sp4.x86_64.rpm","qemu-user-static-8.2.0-86.oe2403sp4.x86_64.rpm"],"aarch64":["qemu-8.2.0-86.oe2403sp4.aarch64.rpm","qemu-block-curl-8.2.0-86.oe2403sp4.aarch64.rpm","qemu-block-iscsi-8.2.0-86.oe2403sp4.aarch64.rpm","qemu-block-rbd-8.2.0-86.oe2403sp4.aarch64.rpm","qemu-block-ssh-8.2.0-86.oe2403sp4.aarch64.rpm","qemu-debuginfo-8.2.0-86.oe2403sp4.aarch64.rpm","qemu-debugsource-8.2.0-86.oe2403sp4.aarch64.rpm","qemu-guest-agent-8.2.0-86.oe2403sp4.aarch64.rpm","qemu-hw-usb-host-8.2.0-86.oe2403sp4.aarch64.rpm","qemu-img-8.2.0-86.oe2403sp4.aarch64.rpm","qemu-system-aarch64-8.2.0-86.oe2403sp4.aarch64.rpm","qemu-system-arm-8.2.0-86.oe2403sp4.aarch64.rpm","qemu-system-riscv-8.2.0-86.oe2403sp4.aarch64.rpm","qemu-system-x86_64-8.2.0-86.oe2403sp4.aarch64.rpm","qemu-user-8.2.0-86.oe2403sp4.aarch64.rpm","qemu-user-binfmt-8.2.0-86.oe2403sp4.aarch64.rpm","qemu-user-static-8.2.0-86.oe2403sp4.aarch64.rpm"],"noarch":["qemu-help-8.2.0-86.oe2403sp4.noarch.rpm"]},"database_specific":{"source":"https://repo.openeuler.org/security/data/osv/OESA-2026-3845.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"}]}