<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T12:04:00.090378+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:39311</id>
    <title>ALSA-2026:39311 — Low: qemu-kvm security update</title>
    <updated>2026-10-03T12:04:00.388583+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: qemu-guest-agent, AlmaLinux:9: qemu-img, AlmaLinux:9: qemu-kvm, AlmaLinux:9: qemu-kvm-audio-pa, AlmaLinux:9: qemu-kvm-block-blkio, AlmaLinux:9: qemu-kvm-block-curl, AlmaLinux:9: qemu-kvm-block-rbd, AlmaLinux:9: qemu-kvm-common, AlmaLinux:9: qemu-kvm-core, AlmaLinux:9: qemu-kvm-device-display-virtio-gpu and 10 more</p>
<p>Kernel-based Virtual Machine (KVM) is a full virtualization solution for Linux on a variety of architectures. The qemu-kvm packages provide the user-space component for running virtual machines that use KVM.</p>
<p>Security Fix(es):</p>
<p>* qemu-kvm: Heap buffer overflow in virtio-blk SCSI request handling (CVE-2026-48914)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:39311"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-48914</id>
    <title>BELL-CVE-2026-48914</title>
    <updated>2026-10-03T12:04:00.388668+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:25: qemu, Alpaquita:stream: qemu</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-48914"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0783</id>
    <title>certfr-2026-avi-0783 — De multiples vulnérabilités ont été découvertes dans Microsoft Azure. Elles permettent à un attaquant de provoquer une…</title>
    <updated>2026-10-03T12:04:00.388703+00:00</updated>
    <content>certfr-2026-avi-0783</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0783"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-361972</id>
    <title>EUVD-2026-361972</title>
    <updated>2026-10-03T12:04:00.388721+00:00</updated>
    <content>EUVD-2026-361972</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-361972"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-48914</id>
    <title>fkie_cve-2026-48914</title>
    <updated>2026-10-03T12:04:00.388733+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in QEMU's virtio-blk device. The issue arises because the device does not properly validate the size of input descriptors before writing data. A malicious guest with high privileges could exploit this vulnerability by submitting a malformed virtio-blk SCSI request, leading to an out-of-bounds write in the host heap memory and a potential denial of service (DoS) for the QEMU process.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-48914"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-4hmh-vx7h-h98p</id>
    <title>GHSA-4hmh-vx7h-h98p</title>
    <updated>2026-10-03T12:04:00.388757+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in QEMU's virtio-blk device. The issue arises because the device does not properly validate the size of input descriptors before writing data. A malicious guest with high privileges could exploit this vulnerability by submitting a malformed virtio-blk SCSI request, leading to an out-of-bounds write in the host heap memory and a potential denial of service (DoS) for the QEMU process.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-4hmh-vx7h-h98p"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-48914</id>
    <title>msrc_CVE-2026-48914 — Qemu-kvm: heap buffer overflow in virtio-blk scsi request handling</title>
    <updated>2026-10-03T12:04:00.388773+00:00</updated>
    <content>msrc_CVE-2026-48914</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-48914"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-2861</id>
    <title>OESA-2026-2861 — qemu security update</title>
    <updated>2026-10-03T12:04:00.388788+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP3: qemu</p>
<p>QEMU is a FAST! processor emulator using dynamic translation to achieve good emulation speed.

Security Fix(es):</p>
<p>A vulnerability, which was classified as critical, has been found in QEMU (Virtualization Software) (version unknown).Using CWE to declare the problem leads to CWE-190. The product performs a calculation that can produce an integer overflow or wraparound, when the logic assumes that the resulting value will always be larger than the original value. This can introduce other weaknesses when the calculation is used for resource management or execution control.Impacted is confidentiality, integrity, and availability.Upgrading eliminates this vulnerability.(CVE-2026-3886)</p>
<p>A flaw was found in QEMU&amp;apos;s virtio-blk device. The issue arises because the device does not properly validate the size of input descriptors before writing data. A malicious guest with high privileges could exploit this vulnerability by submitting a malformed virtio-blk SCSI request, leading to an out-of-bounds write in the host heap memory and a potential denial of service (DoS) for the QEMU process.(CVE-2026-48914)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-2861"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11250-1</id>
    <title>openSUSE-SU-2026:11250-1 — qemu-11.0.2-1.1 on GA media</title>
    <updated>2026-10-03T12:04:00.388819+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>qemu-11.0.2-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11250-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:39311</id>
    <title>RLSA-2026:39311 — Low: qemu-kvm security update</title>
    <updated>2026-10-03T12:04:00.388836+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:9: qemu-kvm</p>
<p>Kernel-based Virtual Machine (KVM) is a full virtualization solution for Linux on a variety of architectures. The qemu-kvm packages provide the user-space component for running virtual machines that use KVM.</p>
<p>Security Fix(es):</p>
<p>* qemu-kvm: Heap buffer overflow in virtio-blk SCSI request handling (CVE-2026-48914)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:39311"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:22550-1</id>
    <title>SUSE-SU-2026:22550-1 — Security update for qemu</title>
    <updated>2026-10-03T12:04:00.388858+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for qemu</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:22550-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-48914</id>
    <title>UBUNTU-CVE-2026-48914</title>
    <updated>2026-10-03T12:04:00.388874+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: qemu, Ubuntu:Pro:16.04:LTS: qemu, Ubuntu:Pro:18.04:LTS: qemu, Ubuntu:Pro:20.04:LTS: qemu, Ubuntu:22.04:LTS: qemu, Ubuntu:24.04:LTS: qemu, Ubuntu:25.10: qemu, Ubuntu:26.04:LTS: qemu, Ubuntu:26.04:LTS: qemu-hwe</p>
<p>A flaw was found in QEMU's virtio-blk device. The issue arises because the device does not properly validate the size of input descriptors before writing data. A malicious guest with high privileges could exploit this vulnerability by submitting a malformed virtio-blk SCSI request, leading to an out-of-bounds write in the host heap memory and a potential denial of service (DoS) for the QEMU process.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-48914"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1908</id>
    <title>WID-SEC-W-2026-1908 — QEMU: Schwachstelle ermöglicht Denial of Service</title>
    <updated>2026-10-03T12:04:00.388907+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann eine Schwachstelle in QEMU ausnutzen, um einen Denial-of-Service Zustand herbeizuführen und möglicherweise um beliebigen Code auf dem Host auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1908"/>
  </entry>
</feed>
