CyberSec.Space Logo
返回 CVE 浏览器

CVE-2026-48914

MEDIUM
6.7
CVSS Severity Score
EPSS Score0.1560%
EPSS Percentile19.41th
Published2026年6月12日
Last Modified2026年6月12日

Vulnerability Description

A flaw was found in QEMU's virtio-blk device. The issue arises because the device does not properly validate the size of input descriptors before writing data. A malicious guest with high privileges could exploit this vulnerability by submitting a malformed virtio-blk SCSI request, leading to an out-of-bounds write in the host heap memory and a potential denial of service (DoS) for the QEMU process.

Affected Platforms (CPE)

No CPE configurations currently published for this record.

References & Advisories

相关漏洞威胁