<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 05:04:29 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:39311 — Low: qemu-kvm security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:39311</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: qemu-guest-agent, AlmaLinux:9: qemu-img, AlmaLinux:9: qemu-kvm, AlmaLinux:9: qemu-kvm-audio-pa, AlmaLinux:9: qemu-kvm-block-blkio, AlmaLinux:9: qemu-kvm-block-curl, AlmaLinux:9: qemu-kvm-block-rbd, AlmaLinux:9: qemu-kvm-common, AlmaLinux:9: qemu-kvm-core, AlmaLinux:9: qemu-kvm-device-display-virtio-gpu and 10 more&lt;/p&gt;
&lt;p&gt;Kernel-based Virtual Machine (KVM) is a full virtualization solution for Linux on a variety of architectures. The qemu-kvm packages provide the user-space component for running virtual machines that use KVM.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* qemu-kvm: Heap buffer overflow in virtio-blk SCSI request handling (CVE-2026-48914)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: qemu-guest-agent, AlmaLinux:9: qemu-img, AlmaLinux:9: qemu-kvm, AlmaLinux:9: qemu-kvm-audio-pa, AlmaLinux:9: qemu-kvm-block-blkio, AlmaLinux:9: qemu-kvm-block-curl, AlmaLinux:9: qemu-kvm-block-rbd, AlmaLinux:9: qemu-kvm-common, AlmaLinux:9: qemu-kvm-core, AlmaLinux:9: qemu-kvm-device-display-virtio-gpu and 10 more&lt;/p&gt;
&lt;p&gt;Kernel-based Virtual Machine (KVM) is a full virtualization solution for Linux on a variety of architectures. The qemu-kvm packages provide the user-space component for running virtual machines that use KVM.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* qemu-kvm: Heap buffer overflow in virtio-blk SCSI request handling (CVE-2026-48914)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:39311</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-48914</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-48914</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:25: qemu, Alpaquita:stream: qemu&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:25: qemu, Alpaquita:stream: qemu&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-48914</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0783 — De multiples vulnérabilités ont été découvertes dans Microsoft Azure. Elles permettent à un attaquant de provoquer une…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0783</link>
      <description>certfr-2026-avi-0783</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0783</guid>
    </item>
    <item>
      <title>EUVD-2026-361972</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-361972</link>
      <description>EUVD-2026-361972</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-361972</guid>
    </item>
    <item>
      <title>fkie_cve-2026-48914</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-48914</link>
      <description>&lt;p&gt;A flaw was found in QEMU&amp;#39;s virtio-blk device. The issue arises because the device does not properly validate the size of input descriptors before writing data. A malicious guest with high privileges could exploit this vulnerability by submitting a malformed virtio-blk SCSI request, leading to an out-of-bounds write in the host heap memory and a potential denial of service (DoS) for the QEMU process.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in QEMU&amp;#39;s virtio-blk device. The issue arises because the device does not properly validate the size of input descriptors before writing data. A malicious guest with high privileges could exploit this vulnerability by submitting a malformed virtio-blk SCSI request, leading to an out-of-bounds write in the host heap memory and a potential denial of service (DoS) for the QEMU process.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-48914</guid>
    </item>
    <item>
      <title>GHSA-4hmh-vx7h-h98p</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-4hmh-vx7h-h98p</link>
      <description>&lt;p&gt;A flaw was found in QEMU&amp;#39;s virtio-blk device. The issue arises because the device does not properly validate the size of input descriptors before writing data. A malicious guest with high privileges could exploit this vulnerability by submitting a malformed virtio-blk SCSI request, leading to an out-of-bounds write in the host heap memory and a potential denial of service (DoS) for the QEMU process.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in QEMU&amp;#39;s virtio-blk device. The issue arises because the device does not properly validate the size of input descriptors before writing data. A malicious guest with high privileges could exploit this vulnerability by submitting a malformed virtio-blk SCSI request, leading to an out-of-bounds write in the host heap memory and a potential denial of service (DoS) for the QEMU process.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-4hmh-vx7h-h98p</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-48914 — Qemu-kvm: heap buffer overflow in virtio-blk scsi request handling</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-48914</link>
      <description>msrc_CVE-2026-48914</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-48914</guid>
    </item>
    <item>
      <title>OESA-2026-2861 — qemu security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-2861</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP3: qemu&lt;/p&gt;
&lt;p&gt;QEMU is a FAST! processor emulator using dynamic translation to achieve good emulation speed.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A vulnerability, which was classified as critical, has been found in QEMU (Virtualization Software) (version unknown).Using CWE to declare the problem leads to CWE-190. The product performs a calculation that can produce an integer overflow or wraparound, when the logic assumes that the resulting value will always be larger than the original value. This can introduce other weaknesses when the calculation is used for resource management or execution control.Impacted is confidentiality, integrity, and availability.Upgrading eliminates this vulnerability.(CVE-2026-3886)&lt;/p&gt;
&lt;p&gt;A flaw was found in QEMU&amp;amp;apos;s virtio-blk device. The issue arises because the device does not properly validate the size of input descriptors before writing data. A malicious guest with high privileges could exploit this vulnerability by submitting a malformed virtio-blk SCSI request, leading to an out-of-bounds write in the host heap memory and a potential denial of service (DoS) for the QEMU process.(CVE-2026-48914)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP3: qemu&lt;/p&gt;
&lt;p&gt;QEMU is a FAST! processor emulator using dynamic translation to achieve good emulation speed.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A vulnerability, which was classified as critical, has been found in QEMU (Virtualization Software) (version unknown).Using CWE to declare the problem leads to CWE-190. The product performs a calculation that can produce an integer overflow or wraparound, when the logic assumes that the resulting value will always be larger than the original value. This can introduce other weaknesses when the calculation is used for resource management or execution control.Impacted is confidentiality, integrity, and availability.Upgrading eliminates this vulnerability.(CVE-2026-3886)&lt;/p&gt;
&lt;p&gt;A flaw was found in QEMU&amp;amp;apos;s virtio-blk device. The issue arises because the device does not properly validate the size of input descriptors before writing data. A malicious guest with high privileges could exploit this vulnerability by submitting a malformed virtio-blk SCSI request, leading to an out-of-bounds write in the host heap memory and a potential denial of service (DoS) for the QEMU process.(CVE-2026-48914)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-2861</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11250-1 — qemu-11.0.2-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11250-1</link>
      <description>&lt;p&gt;qemu-11.0.2-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;qemu-11.0.2-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11250-1</guid>
    </item>
    <item>
      <title>RLSA-2026:39311 — Low: qemu-kvm security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:39311</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:9: qemu-kvm&lt;/p&gt;
&lt;p&gt;Kernel-based Virtual Machine (KVM) is a full virtualization solution for Linux on a variety of architectures. The qemu-kvm packages provide the user-space component for running virtual machines that use KVM.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* qemu-kvm: Heap buffer overflow in virtio-blk SCSI request handling (CVE-2026-48914)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:9: qemu-kvm&lt;/p&gt;
&lt;p&gt;Kernel-based Virtual Machine (KVM) is a full virtualization solution for Linux on a variety of architectures. The qemu-kvm packages provide the user-space component for running virtual machines that use KVM.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* qemu-kvm: Heap buffer overflow in virtio-blk SCSI request handling (CVE-2026-48914)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:39311</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:22550-1 — Security update for qemu</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:22550-1</link>
      <description>&lt;p&gt;Security update for qemu&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for qemu&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:22550-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-48914</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-48914</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: qemu, Ubuntu:Pro:16.04:LTS: qemu, Ubuntu:Pro:18.04:LTS: qemu, Ubuntu:Pro:20.04:LTS: qemu, Ubuntu:22.04:LTS: qemu, Ubuntu:24.04:LTS: qemu, Ubuntu:25.10: qemu, Ubuntu:26.04:LTS: qemu, Ubuntu:26.04:LTS: qemu-hwe&lt;/p&gt;
&lt;p&gt;A flaw was found in QEMU&amp;#39;s virtio-blk device. The issue arises because the device does not properly validate the size of input descriptors before writing data. A malicious guest with high privileges could exploit this vulnerability by submitting a malformed virtio-blk SCSI request, leading to an out-of-bounds write in the host heap memory and a potential denial of service (DoS) for the QEMU process.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: qemu, Ubuntu:Pro:16.04:LTS: qemu, Ubuntu:Pro:18.04:LTS: qemu, Ubuntu:Pro:20.04:LTS: qemu, Ubuntu:22.04:LTS: qemu, Ubuntu:24.04:LTS: qemu, Ubuntu:25.10: qemu, Ubuntu:26.04:LTS: qemu, Ubuntu:26.04:LTS: qemu-hwe&lt;/p&gt;
&lt;p&gt;A flaw was found in QEMU&amp;#39;s virtio-blk device. The issue arises because the device does not properly validate the size of input descriptors before writing data. A malicious guest with high privileges could exploit this vulnerability by submitting a malformed virtio-blk SCSI request, leading to an out-of-bounds write in the host heap memory and a potential denial of service (DoS) for the QEMU process.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-48914</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1908 — QEMU: Schwachstelle ermöglicht Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1908</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in QEMU ausnutzen, um einen Denial-of-Service Zustand herbeizuführen und möglicherweise um beliebigen Code auf dem Host auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in QEMU ausnutzen, um einen Denial-of-Service Zustand herbeizuführen und möglicherweise um beliebigen Code auf dem Host auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1908</guid>
    </item>
  </channel>
</rss>
