Search

Find a vulnerability

Search criteria

    Related vulnerabilities

    BELL-CVE-2026-3886 (CVE-2026-3886)

    Vulnerability from osv_bellsoft – Published: 2026-07-11 06:04 – Updated: 2026-08-14 22:55 – Source website
    VLAI

    {
      "affected": [
        {
          "package": {
            "ecosystem": "Alpaquita:25",
            "name": "qemu",
            "purl": "pkg:apk/alpaquita/qemu?arch=source\u0026distro=25"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "10.0.0-r1"
                },
                {
                  "fixed": "10.0.12-r0"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "package": {
            "ecosystem": "Alpaquita:stream",
            "name": "qemu",
            "purl": "pkg:apk/alpaquita/qemu?arch=source\u0026distro=stream"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "8.0.2-r0"
                },
                {
                  "fixed": "11.0.0-r0"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        }
      ],
      "id": "BELL-CVE-2026-3886",
      "modified": "2026-08-14T22:55:03.51218Z",
      "published": "2026-07-11T06:04:30.597904Z",
      "references": [
        {
          "type": "ADVISORY",
          "url": "https://docs.bell-sw.com/security/cves/CVE-2026-3886"
        }
      ],
      "schema_version": "1.7.4",
      "upstream": [
        "CVE-2026-3886"
      ]
    }

    OESA-2026-2861 (CVE-2026-3886)

    Vulnerability from osv_openeuler – Published: 2026-07-06 11:11 – Updated: 2026-08-06 11:11 – Source website
    VLAI
    Summary
    qemu security update
    Details

    QEMU is a FAST! processor emulator using dynamic translation to achieve good emulation speed.

    Security Fix(es):

    A vulnerability, which was classified as critical, has been found in QEMU (Virtualization Software) (version unknown).Using CWE to declare the problem leads to CWE-190. The product performs a calculation that can produce an integer overflow or wraparound, when the logic assumes that the resulting value will always be larger than the original value. This can introduce other weaknesses when the calculation is used for resource management or execution control.Impacted is confidentiality, integrity, and availability.Upgrading eliminates this vulnerability.(CVE-2026-3886)

    A flaw was found in QEMU's virtio-blk device. The issue arises because the device does not properly validate the size of input descriptors before writing data. A malicious guest with high privileges could exploit this vulnerability by submitting a malformed virtio-blk SCSI request, leading to an out-of-bounds write in the host heap memory and a potential denial of service (DoS) for the QEMU process.(CVE-2026-48914)


    {
      "affected": [
        {
          "ecosystem_specific": {
            "aarch64": [
              "qemu-8.2.0-80.oe2403sp3.aarch64.rpm",
              "qemu-block-curl-8.2.0-80.oe2403sp3.aarch64.rpm",
              "qemu-block-iscsi-8.2.0-80.oe2403sp3.aarch64.rpm",
              "qemu-block-rbd-8.2.0-80.oe2403sp3.aarch64.rpm",
              "qemu-block-ssh-8.2.0-80.oe2403sp3.aarch64.rpm",
              "qemu-debuginfo-8.2.0-80.oe2403sp3.aarch64.rpm",
              "qemu-debugsource-8.2.0-80.oe2403sp3.aarch64.rpm",
              "qemu-guest-agent-8.2.0-80.oe2403sp3.aarch64.rpm",
              "qemu-hw-usb-host-8.2.0-80.oe2403sp3.aarch64.rpm",
              "qemu-img-8.2.0-80.oe2403sp3.aarch64.rpm",
              "qemu-system-aarch64-8.2.0-80.oe2403sp3.aarch64.rpm",
              "qemu-system-arm-8.2.0-80.oe2403sp3.aarch64.rpm",
              "qemu-system-riscv-8.2.0-80.oe2403sp3.aarch64.rpm",
              "qemu-system-x86_64-8.2.0-80.oe2403sp3.aarch64.rpm",
              "qemu-user-8.2.0-80.oe2403sp3.aarch64.rpm",
              "qemu-user-binfmt-8.2.0-80.oe2403sp3.aarch64.rpm",
              "qemu-user-static-8.2.0-80.oe2403sp3.aarch64.rpm"
            ],
            "noarch": [
              "qemu-help-8.2.0-80.oe2403sp3.noarch.rpm"
            ],
            "src": [
              "qemu-8.2.0-80.oe2403sp3.src.rpm"
            ],
            "x86_64": [
              "qemu-8.2.0-80.oe2403sp3.x86_64.rpm",
              "qemu-block-curl-8.2.0-80.oe2403sp3.x86_64.rpm",
              "qemu-block-iscsi-8.2.0-80.oe2403sp3.x86_64.rpm",
              "qemu-block-rbd-8.2.0-80.oe2403sp3.x86_64.rpm",
              "qemu-block-ssh-8.2.0-80.oe2403sp3.x86_64.rpm",
              "qemu-debuginfo-8.2.0-80.oe2403sp3.x86_64.rpm",
              "qemu-debugsource-8.2.0-80.oe2403sp3.x86_64.rpm",
              "qemu-guest-agent-8.2.0-80.oe2403sp3.x86_64.rpm",
              "qemu-hw-usb-host-8.2.0-80.oe2403sp3.x86_64.rpm",
              "qemu-img-8.2.0-80.oe2403sp3.x86_64.rpm",
              "qemu-seabios-8.2.0-80.oe2403sp3.x86_64.rpm",
              "qemu-system-aarch64-8.2.0-80.oe2403sp3.x86_64.rpm",
              "qemu-system-arm-8.2.0-80.oe2403sp3.x86_64.rpm",
              "qemu-system-riscv-8.2.0-80.oe2403sp3.x86_64.rpm",
              "qemu-system-x86_64-8.2.0-80.oe2403sp3.x86_64.rpm",
              "qemu-user-8.2.0-80.oe2403sp3.x86_64.rpm",
              "qemu-user-binfmt-8.2.0-80.oe2403sp3.x86_64.rpm",
              "qemu-user-static-8.2.0-80.oe2403sp3.x86_64.rpm"
            ]
          },
          "package": {
            "ecosystem": "openEuler:24.03-LTS-SP3",
            "name": "qemu",
            "purl": "pkg:rpm/openEuler/qemu\u0026distro=openEuler-24.03-LTS-SP3"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "8.2.0-80.oe2403sp3"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        }
      ],
      "database_specific": {
        "severity": "High"
      },
      "details": "QEMU is a FAST! processor emulator using dynamic translation to achieve good emulation speed.\r\n\r\nSecurity Fix(es):\n\nA vulnerability, which was classified as critical, has been found in QEMU (Virtualization Software) (version unknown).Using CWE to declare the problem leads to CWE-190. The product performs a calculation that can produce an integer overflow or wraparound, when the logic assumes that the resulting value will always be larger than the original value. This can introduce other weaknesses when the calculation is used for resource management or execution control.Impacted is confidentiality, integrity, and availability.Upgrading eliminates this vulnerability.(CVE-2026-3886)\n\nA flaw was found in QEMU\u0026apos;s virtio-blk device. The issue arises because the device does not properly validate the size of input descriptors before writing data. A malicious guest with high privileges could exploit this vulnerability by submitting a malformed virtio-blk SCSI request, leading to an out-of-bounds write in the host heap memory and a potential denial of service (DoS) for the QEMU process.(CVE-2026-48914)",
      "id": "OESA-2026-2861",
      "modified": "2026-08-06T11:11:46Z",
      "published": "2026-07-06T11:11:46Z",
      "references": [
        {
          "type": "ADVISORY",
          "url": "https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2861"
        },
        {
          "type": "ADVISORY",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-3886"
        },
        {
          "type": "ADVISORY",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-48914"
        }
      ],
      "schema_version": "1.7.2",
      "severity": [
        {
          "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
          "type": "CVSS_V3"
        }
      ],
      "summary": "qemu security update",
      "upstream": [
        "CVE-2026-3886",
        "CVE-2026-48914"
      ]
    }

    OESA-2026-2952 (CVE-2026-3886)

    Vulnerability from osv_openeuler – Published: 2026-07-09 11:11 – Updated: 2026-08-06 11:11 – Source website
    VLAI
    Summary
    qemu security update
    Details

    QEMU is a FAST! processor emulator using dynamic translation to achieve good emulation speed.

    Security Fix(es):

    A vulnerability, which was classified as critical, has been found in QEMU (Virtualization Software) (version unknown).Using CWE to declare the problem leads to CWE-190. The product performs a calculation that can produce an integer overflow or wraparound, when the logic assumes that the resulting value will always be larger than the original value. This can introduce other weaknesses when the calculation is used for resource management or execution control.Impacted is confidentiality, integrity, and availability.Upgrading eliminates this vulnerability.(CVE-2026-3886)

    A flaw was found in QEMU's virtio-blk device. The issue arises because the device does not properly validate the size of input descriptors before writing data. A malicious guest with high privileges could exploit this vulnerability by submitting a malformed virtio-blk SCSI request, leading to an out-of-bounds write in the host heap memory and a potential denial of service (DoS) for the QEMU process.(CVE-2026-48914)


    {
      "affected": [
        {
          "ecosystem_specific": {
            "aarch64": [
              "qemu-8.2.0-56.oe2403sp1.aarch64.rpm",
              "qemu-block-curl-8.2.0-56.oe2403sp1.aarch64.rpm",
              "qemu-block-iscsi-8.2.0-56.oe2403sp1.aarch64.rpm",
              "qemu-block-rbd-8.2.0-56.oe2403sp1.aarch64.rpm",
              "qemu-block-ssh-8.2.0-56.oe2403sp1.aarch64.rpm",
              "qemu-debuginfo-8.2.0-56.oe2403sp1.aarch64.rpm",
              "qemu-debugsource-8.2.0-56.oe2403sp1.aarch64.rpm",
              "qemu-guest-agent-8.2.0-56.oe2403sp1.aarch64.rpm",
              "qemu-hw-usb-host-8.2.0-56.oe2403sp1.aarch64.rpm",
              "qemu-img-8.2.0-56.oe2403sp1.aarch64.rpm",
              "qemu-system-aarch64-8.2.0-56.oe2403sp1.aarch64.rpm",
              "qemu-system-arm-8.2.0-56.oe2403sp1.aarch64.rpm",
              "qemu-system-riscv-8.2.0-56.oe2403sp1.aarch64.rpm",
              "qemu-system-x86_64-8.2.0-56.oe2403sp1.aarch64.rpm",
              "qemu-user-8.2.0-56.oe2403sp1.aarch64.rpm",
              "qemu-user-binfmt-8.2.0-56.oe2403sp1.aarch64.rpm",
              "qemu-user-static-8.2.0-56.oe2403sp1.aarch64.rpm"
            ],
            "noarch": [
              "qemu-help-8.2.0-56.oe2403sp1.noarch.rpm"
            ],
            "src": [
              "qemu-8.2.0-56.oe2403sp1.src.rpm"
            ],
            "x86_64": [
              "qemu-8.2.0-56.oe2403sp1.x86_64.rpm",
              "qemu-block-curl-8.2.0-56.oe2403sp1.x86_64.rpm",
              "qemu-block-iscsi-8.2.0-56.oe2403sp1.x86_64.rpm",
              "qemu-block-rbd-8.2.0-56.oe2403sp1.x86_64.rpm",
              "qemu-block-ssh-8.2.0-56.oe2403sp1.x86_64.rpm",
              "qemu-debuginfo-8.2.0-56.oe2403sp1.x86_64.rpm",
              "qemu-debugsource-8.2.0-56.oe2403sp1.x86_64.rpm",
              "qemu-guest-agent-8.2.0-56.oe2403sp1.x86_64.rpm",
              "qemu-hw-usb-host-8.2.0-56.oe2403sp1.x86_64.rpm",
              "qemu-img-8.2.0-56.oe2403sp1.x86_64.rpm",
              "qemu-seabios-8.2.0-56.oe2403sp1.x86_64.rpm",
              "qemu-system-aarch64-8.2.0-56.oe2403sp1.x86_64.rpm",
              "qemu-system-arm-8.2.0-56.oe2403sp1.x86_64.rpm",
              "qemu-system-riscv-8.2.0-56.oe2403sp1.x86_64.rpm",
              "qemu-system-x86_64-8.2.0-56.oe2403sp1.x86_64.rpm",
              "qemu-user-8.2.0-56.oe2403sp1.x86_64.rpm",
              "qemu-user-binfmt-8.2.0-56.oe2403sp1.x86_64.rpm",
              "qemu-user-static-8.2.0-56.oe2403sp1.x86_64.rpm"
            ]
          },
          "package": {
            "ecosystem": "openEuler:24.03-LTS-SP1",
            "name": "qemu",
            "purl": "pkg:rpm/openEuler/qemu\u0026distro=openEuler-24.03-LTS-SP1"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "8.2.0-56.oe2403sp1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        }
      ],
      "database_specific": {
        "severity": "High"
      },
      "details": "QEMU is a FAST! processor emulator using dynamic translation to achieve good emulation speed.\r\n\r\nSecurity Fix(es):\n\nA vulnerability, which was classified as critical, has been found in QEMU (Virtualization Software) (version unknown).Using CWE to declare the problem leads to CWE-190. The product performs a calculation that can produce an integer overflow or wraparound, when the logic assumes that the resulting value will always be larger than the original value. This can introduce other weaknesses when the calculation is used for resource management or execution control.Impacted is confidentiality, integrity, and availability.Upgrading eliminates this vulnerability.(CVE-2026-3886)\n\nA flaw was found in QEMU\u0026apos;s virtio-blk device. The issue arises because the device does not properly validate the size of input descriptors before writing data. A malicious guest with high privileges could exploit this vulnerability by submitting a malformed virtio-blk SCSI request, leading to an out-of-bounds write in the host heap memory and a potential denial of service (DoS) for the QEMU process.(CVE-2026-48914)",
      "id": "OESA-2026-2952",
      "modified": "2026-08-06T11:11:51Z",
      "published": "2026-07-09T11:11:51Z",
      "references": [
        {
          "type": "ADVISORY",
          "url": "https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2952"
        },
        {
          "type": "ADVISORY",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-3886"
        },
        {
          "type": "ADVISORY",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-48914"
        }
      ],
      "schema_version": "1.7.2",
      "severity": [
        {
          "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
          "type": "CVSS_V3"
        }
      ],
      "summary": "qemu security update",
      "upstream": [
        "CVE-2026-3886",
        "CVE-2026-48914"
      ]
    }

    OPENSUSE-SU-2026:21253-1

    Vulnerability from csaf_opensuse - Published: 2026-07-07 17:20 - Updated: 2026-09-17 17:38
    Summary
    Security update for qemu
    Severity
    Important
    Scope
    3 vulnerabilities in this advisory, including CVE-2026-3886.
    CVE-2026-3886
    Recommended: 193 products
    Open the full advisory

    SUSE-SU-2026:22550-1

    Vulnerability from csaf_suse - Published: 2026-07-07 17:18 - Updated: 2026-09-17 16:00
    Summary
    Security update for qemu
    Severity
    Important
    Scope
    3 vulnerabilities in this advisory, including CVE-2026-3886.
    CVE-2026-3886
    Recommended: 83 products
    Open the full advisory

    SUSE-SU-2026:22576-1

    Vulnerability from csaf_suse - Published: 2026-07-07 17:18 - Updated: 2026-09-17 16:00
    Summary
    Security update for qemu
    Severity
    Important
    Scope
    3 vulnerabilities in this advisory, including CVE-2026-3886.
    CVE-2026-3886
    Recommended: 266 products
    Open the full advisory

    SUSE-SU-2026:23351-1

    Vulnerability from csaf_suse - Published: 2026-08-27 13:26 - Updated: 2026-09-17 16:19
    Summary
    Security update for qemu
    Severity
    Important
    Scope
    1 vulnerability in this advisory, including CVE-2026-3886.
    CVE-2026-3886
    Recommended: 102 products
    Open the full advisory

    SUSE-SU-2026:23362-1

    Vulnerability from csaf_suse - Published: 2026-08-27 12:01 - Updated: 2026-09-20 18:41
    Summary
    Security update for qemu
    Severity
    Important
    Scope
    1 vulnerability in this advisory, including CVE-2026-3886.
    CVE-2026-3886
    Recommended: 68 products
    Open the full advisory

    SUSE-SU-2026:3806-1

    Vulnerability from csaf_suse - Published: 2026-08-26 09:07 - Updated: 2026-09-17 16:43
    Summary
    Security update for qemu
    Severity
    Important
    Scope
    1 vulnerability in this advisory, including CVE-2026-3886.
    CVE-2026-3886
    Recommended: 384 products
    Open the full advisory

    UBUNTU-CVE-2026-3886 (CVE-2026-3886)

    Vulnerability from osv_ubuntu – Published: 2026-07-09 00:00 – Updated: 2026-08-27 13:49 – Source website
    VLAI
    Details

    [virtio-gpu: fix overflow check when allocating 2d image]

    Severity
    N/A (UNKNOWN)

    {
      "affected": [
        {
          "ecosystem_specific": {
            "binaries": [
              {
                "binary_name": "qemu-block-extra",
                "binary_version": "1:8.2.2+ds-0ubuntu1.18"
              },
              {
                "binary_name": "qemu-block-supplemental",
                "binary_version": "1:8.2.2+ds-0ubuntu1.18"
              },
              {
                "binary_name": "qemu-guest-agent",
                "binary_version": "1:8.2.2+ds-0ubuntu1.18"
              },
              {
                "binary_name": "qemu-system",
                "binary_version": "1:8.2.2+ds-0ubuntu1.18"
              },
              {
                "binary_name": "qemu-system-arm",
                "binary_version": "1:8.2.2+ds-0ubuntu1.18"
              },
              {
                "binary_name": "qemu-system-common",
                "binary_version": "1:8.2.2+ds-0ubuntu1.18"
              },
              {
                "binary_name": "qemu-system-data",
                "binary_version": "1:8.2.2+ds-0ubuntu1.18"
              },
              {
                "binary_name": "qemu-system-gui",
                "binary_version": "1:8.2.2+ds-0ubuntu1.18"
              },
              {
                "binary_name": "qemu-system-mips",
                "binary_version": "1:8.2.2+ds-0ubuntu1.18"
              },
              {
                "binary_name": "qemu-system-misc",
                "binary_version": "1:8.2.2+ds-0ubuntu1.18"
              },
              {
                "binary_name": "qemu-system-modules-opengl",
                "binary_version": "1:8.2.2+ds-0ubuntu1.18"
              },
              {
                "binary_name": "qemu-system-modules-spice",
                "binary_version": "1:8.2.2+ds-0ubuntu1.18"
              },
              {
                "binary_name": "qemu-system-ppc",
                "binary_version": "1:8.2.2+ds-0ubuntu1.18"
              },
              {
                "binary_name": "qemu-system-s390x",
                "binary_version": "1:8.2.2+ds-0ubuntu1.18"
              },
              {
                "binary_name": "qemu-system-sparc",
                "binary_version": "1:8.2.2+ds-0ubuntu1.18"
              },
              {
                "binary_name": "qemu-system-x86",
                "binary_version": "1:8.2.2+ds-0ubuntu1.18"
              },
              {
                "binary_name": "qemu-system-x86-xen",
                "binary_version": "1:8.2.2+ds-0ubuntu1.18"
              },
              {
                "binary_name": "qemu-system-xen",
                "binary_version": "1:8.2.2+ds-0ubuntu1.18"
              },
              {
                "binary_name": "qemu-user",
                "binary_version": "1:8.2.2+ds-0ubuntu1.18"
              },
              {
                "binary_name": "qemu-user-binfmt",
                "binary_version": "1:8.2.2+ds-0ubuntu1.18"
              },
              {
                "binary_name": "qemu-user-static",
                "binary_version": "1:8.2.2+ds-0ubuntu1.18"
              },
              {
                "binary_name": "qemu-utils",
                "binary_version": "1:8.2.2+ds-0ubuntu1.18"
              }
            ],
            "priority_reason": "Vulnerability allows for VM escape"
          },
          "package": {
            "ecosystem": "Ubuntu:24.04:LTS",
            "name": "qemu",
            "purl": "pkg:deb/ubuntu/qemu@1:8.2.2+ds-0ubuntu1.18?arch=source\u0026distro=noble"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "1:8.0.4+dfsg-1ubuntu3",
            "1:8.0.4+dfsg-1ubuntu4",
            "1:8.0.4+dfsg-1ubuntu5",
            "1:8.1.3+ds-1ubuntu2",
            "1:8.2.1+ds-1ubuntu1",
            "1:8.2.1+ds-1ubuntu8",
            "1:8.2.1+ds-1ubuntu9",
            "1:8.2.2+ds-0ubuntu1",
            "1:8.2.2+ds-0ubuntu1.2",
            "1:8.2.2+ds-0ubuntu1.4",
            "1:8.2.2+ds-0ubuntu1.5",
            "1:8.2.2+ds-0ubuntu1.6",
            "1:8.2.2+ds-0ubuntu1.7",
            "1:8.2.2+ds-0ubuntu1.8",
            "1:8.2.2+ds-0ubuntu1.9",
            "1:8.2.2+ds-0ubuntu1.10",
            "1:8.2.2+ds-0ubuntu1.11",
            "1:8.2.2+ds-0ubuntu1.12",
            "1:8.2.2+ds-0ubuntu1.13",
            "1:8.2.2+ds-0ubuntu1.14",
            "1:8.2.2+ds-0ubuntu1.15",
            "1:8.2.2+ds-0ubuntu1.16",
            "1:8.2.2+ds-0ubuntu1.17",
            "1:8.2.2+ds-0ubuntu1.18"
          ]
        },
        {
          "ecosystem_specific": {
            "binaries": [
              {
                "binary_name": "qemu-block-extra",
                "binary_version": "1:10.1.0+ds-5ubuntu2.7"
              },
              {
                "binary_name": "qemu-block-supplemental",
                "binary_version": "1:10.1.0+ds-5ubuntu2.7"
              },
              {
                "binary_name": "qemu-guest-agent",
                "binary_version": "1:10.1.0+ds-5ubuntu2.7"
              },
              {
                "binary_name": "qemu-system",
                "binary_version": "1:10.1.0+ds-5ubuntu2.7"
              },
              {
                "binary_name": "qemu-system-arm",
                "binary_version": "1:10.1.0+ds-5ubuntu2.7"
              },
              {
                "binary_name": "qemu-system-common",
                "binary_version": "1:10.1.0+ds-5ubuntu2.7"
              },
              {
                "binary_name": "qemu-system-data",
                "binary_version": "1:10.1.0+ds-5ubuntu2.7"
              },
              {
                "binary_name": "qemu-system-gui",
                "binary_version": "1:10.1.0+ds-5ubuntu2.7"
              },
              {
                "binary_name": "qemu-system-mips",
                "binary_version": "1:10.1.0+ds-5ubuntu2.7"
              },
              {
                "binary_name": "qemu-system-misc",
                "binary_version": "1:10.1.0+ds-5ubuntu2.7"
              },
              {
                "binary_name": "qemu-system-modules-opengl",
                "binary_version": "1:10.1.0+ds-5ubuntu2.7"
              },
              {
                "binary_name": "qemu-system-modules-spice",
                "binary_version": "1:10.1.0+ds-5ubuntu2.7"
              },
              {
                "binary_name": "qemu-system-ppc",
                "binary_version": "1:10.1.0+ds-5ubuntu2.7"
              },
              {
                "binary_name": "qemu-system-riscv",
                "binary_version": "1:10.1.0+ds-5ubuntu2.7"
              },
              {
                "binary_name": "qemu-system-s390x",
                "binary_version": "1:10.1.0+ds-5ubuntu2.7"
              },
              {
                "binary_name": "qemu-system-sparc",
                "binary_version": "1:10.1.0+ds-5ubuntu2.7"
              },
              {
                "binary_name": "qemu-system-x86",
                "binary_version": "1:10.1.0+ds-5ubuntu2.7"
              },
              {
                "binary_name": "qemu-system-x86-xen",
                "binary_version": "1:10.1.0+ds-5ubuntu2.7"
              },
              {
                "binary_name": "qemu-system-xen",
                "binary_version": "1:10.1.0+ds-5ubuntu2.7"
              },
              {
                "binary_name": "qemu-user",
                "binary_version": "1:10.1.0+ds-5ubuntu2.7"
              },
              {
                "binary_name": "qemu-user-binfmt",
                "binary_version": "1:10.1.0+ds-5ubuntu2.7"
              },
              {
                "binary_name": "qemu-utils",
                "binary_version": "1:10.1.0+ds-5ubuntu2.7"
              }
            ],
            "priority_reason": "Vulnerability allows for VM escape"
          },
          "package": {
            "ecosystem": "Ubuntu:25.10",
            "name": "qemu",
            "purl": "pkg:deb/ubuntu/qemu@1:10.1.0+ds-5ubuntu2.7?arch=source\u0026distro=questing"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "1:9.2.1+ds-1ubuntu5",
            "1:10.0.2+ds-1ubuntu1",
            "1:10.0.2+ds-1ubuntu2",
            "1:10.1.0+ds-1ubuntu1",
            "1:10.1.0+ds-5ubuntu1",
            "1:10.1.0+ds-5ubuntu2",
            "1:10.1.0+ds-5ubuntu2.1",
            "1:10.1.0+ds-5ubuntu2.2",
            "1:10.1.0+ds-5ubuntu2.4",
            "1:10.1.0+ds-5ubuntu2.5",
            "1:10.1.0+ds-5ubuntu2.6",
            "1:10.1.0+ds-5ubuntu2.7"
          ]
        },
        {
          "ecosystem_specific": {
            "binaries": [
              {
                "binary_name": "qemu-block-extra",
                "binary_version": "1:10.2.1+ds-1ubuntu3.2"
              },
              {
                "binary_name": "qemu-block-supplemental",
                "binary_version": "1:10.2.1+ds-1ubuntu3.2"
              },
              {
                "binary_name": "qemu-guest-agent",
                "binary_version": "1:10.2.1+ds-1ubuntu3.2"
              },
              {
                "binary_name": "qemu-system",
                "binary_version": "1:10.2.1+ds-1ubuntu3.2"
              },
              {
                "binary_name": "qemu-system-arm",
                "binary_version": "1:10.2.1+ds-1ubuntu3.2"
              },
              {
                "binary_name": "qemu-system-common",
                "binary_version": "1:10.2.1+ds-1ubuntu3.2"
              },
              {
                "binary_name": "qemu-system-data",
                "binary_version": "1:10.2.1+ds-1ubuntu3.2"
              },
              {
                "binary_name": "qemu-system-gui",
                "binary_version": "1:10.2.1+ds-1ubuntu3.2"
              },
              {
                "binary_name": "qemu-system-mips",
                "binary_version": "1:10.2.1+ds-1ubuntu3.2"
              },
              {
                "binary_name": "qemu-system-misc",
                "binary_version": "1:10.2.1+ds-1ubuntu3.2"
              },
              {
                "binary_name": "qemu-system-modules-opengl",
                "binary_version": "1:10.2.1+ds-1ubuntu3.2"
              },
              {
                "binary_name": "qemu-system-modules-spice",
                "binary_version": "1:10.2.1+ds-1ubuntu3.2"
              },
              {
                "binary_name": "qemu-system-ppc",
                "binary_version": "1:10.2.1+ds-1ubuntu3.2"
              },
              {
                "binary_name": "qemu-system-riscv",
                "binary_version": "1:10.2.1+ds-1ubuntu3.2"
              },
              {
                "binary_name": "qemu-system-s390x",
                "binary_version": "1:10.2.1+ds-1ubuntu3.2"
              },
              {
                "binary_name": "qemu-system-sparc",
                "binary_version": "1:10.2.1+ds-1ubuntu3.2"
              },
              {
                "binary_name": "qemu-system-x86",
                "binary_version": "1:10.2.1+ds-1ubuntu3.2"
              },
              {
                "binary_name": "qemu-system-x86-xen",
                "binary_version": "1:10.2.1+ds-1ubuntu3.2"
              },
              {
                "binary_name": "qemu-system-xen",
                "binary_version": "1:10.2.1+ds-1ubuntu3.2"
              },
              {
                "binary_name": "qemu-user",
                "binary_version": "1:10.2.1+ds-1ubuntu3.2"
              },
              {
                "binary_name": "qemu-user-binfmt",
                "binary_version": "1:10.2.1+ds-1ubuntu3.2"
              },
              {
                "binary_name": "qemu-utils",
                "binary_version": "1:10.2.1+ds-1ubuntu3.2"
              },
              {
                "binary_name": "ubuntu-virt",
                "binary_version": "1:10.2.1+ds-1ubuntu3.2"
              }
            ],
            "priority_reason": "Vulnerability allows for VM escape"
          },
          "package": {
            "ecosystem": "Ubuntu:26.04:LTS",
            "name": "qemu",
            "purl": "pkg:deb/ubuntu/qemu@1:10.2.1+ds-1ubuntu3.2?arch=source\u0026distro=resolute"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "1:10.1.0+ds-5ubuntu2",
            "1:10.1.0+ds-5ubuntu3",
            "1:10.1.0+ds-5ubuntu4",
            "1:10.1.0+ds-5ubuntu5",
            "1:10.2.1+ds-1ubuntu1",
            "1:10.2.1+ds-1ubuntu2",
            "1:10.2.1+ds-1ubuntu3",
            "1:10.2.1+ds-1ubuntu3.1",
            "1:10.2.1+ds-1ubuntu3.2"
          ]
        },
        {
          "ecosystem_specific": {
            "binaries": [
              {
                "binary_name": "qemu-block-extra-hwe",
                "binary_version": "1:10.2.1+ds-1ubuntu4.3"
              },
              {
                "binary_name": "qemu-block-supplemental-hwe",
                "binary_version": "1:10.2.1+ds-1ubuntu4.3"
              },
              {
                "binary_name": "qemu-guest-agent-hwe",
                "binary_version": "1:10.2.1+ds-1ubuntu4.3"
              },
              {
                "binary_name": "qemu-system-arm-hwe",
                "binary_version": "1:10.2.1+ds-1ubuntu4.3"
              },
              {
                "binary_name": "qemu-system-common-hwe",
                "binary_version": "1:10.2.1+ds-1ubuntu4.3"
              },
              {
                "binary_name": "qemu-system-data-hwe",
                "binary_version": "1:10.2.1+ds-1ubuntu4.3"
              },
              {
                "binary_name": "qemu-system-gui-hwe",
                "binary_version": "1:10.2.1+ds-1ubuntu4.3"
              },
              {
                "binary_name": "qemu-system-hwe",
                "binary_version": "1:10.2.1+ds-1ubuntu4.3"
              },
              {
                "binary_name": "qemu-system-mips-hwe",
                "binary_version": "1:10.2.1+ds-1ubuntu4.3"
              },
              {
                "binary_name": "qemu-system-misc-hwe",
                "binary_version": "1:10.2.1+ds-1ubuntu4.3"
              },
              {
                "binary_name": "qemu-system-modules-opengl-hwe",
                "binary_version": "1:10.2.1+ds-1ubuntu4.3"
              },
              {
                "binary_name": "qemu-system-modules-spice-hwe",
                "binary_version": "1:10.2.1+ds-1ubuntu4.3"
              },
              {
                "binary_name": "qemu-system-ppc-hwe",
                "binary_version": "1:10.2.1+ds-1ubuntu4.3"
              },
              {
                "binary_name": "qemu-system-riscv-hwe",
                "binary_version": "1:10.2.1+ds-1ubuntu4.3"
              },
              {
                "binary_name": "qemu-system-s390x-hwe",
                "binary_version": "1:10.2.1+ds-1ubuntu4.3"
              },
              {
                "binary_name": "qemu-system-sparc-hwe",
                "binary_version": "1:10.2.1+ds-1ubuntu4.3"
              },
              {
                "binary_name": "qemu-system-x86-hwe",
                "binary_version": "1:10.2.1+ds-1ubuntu4.3"
              },
              {
                "binary_name": "qemu-system-x86-xen-hwe",
                "binary_version": "1:10.2.1+ds-1ubuntu4.3"
              },
              {
                "binary_name": "qemu-system-xen-hwe",
                "binary_version": "1:10.2.1+ds-1ubuntu4.3"
              },
              {
                "binary_name": "qemu-user-binfmt-hwe",
                "binary_version": "1:10.2.1+ds-1ubuntu4.3"
              },
              {
                "binary_name": "qemu-user-hwe",
                "binary_version": "1:10.2.1+ds-1ubuntu4.3"
              },
              {
                "binary_name": "qemu-utils-hwe",
                "binary_version": "1:10.2.1+ds-1ubuntu4.3"
              },
              {
                "binary_name": "ubuntu-helper-virt-hwe",
                "binary_version": "1:10.2.1+ds-1ubuntu4.3"
              },
              {
                "binary_name": "ubuntu-virt-hwe",
                "binary_version": "1:10.2.1+ds-1ubuntu4.3"
              }
            ],
            "priority_reason": "Vulnerability allows for VM escape"
          },
          "package": {
            "ecosystem": "Ubuntu:26.04:LTS",
            "name": "qemu-hwe",
            "purl": "pkg:deb/ubuntu/qemu-hwe@1:10.2.1+ds-1ubuntu4.3?arch=source\u0026distro=resolute"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "1:10.2.1+ds-1ubuntu2",
            "1:10.2.1+ds-1ubuntu4",
            "1:10.2.1+ds-1ubuntu4.2",
            "1:10.2.1+ds-1ubuntu4.3"
          ]
        }
      ],
      "aliases": [],
      "details": "[virtio-gpu: fix overflow check when allocating 2d image]",
      "id": "UBUNTU-CVE-2026-3886",
      "modified": "2026-08-27T13:49:50Z",
      "published": "2026-07-09T00:00:00Z",
      "references": [
        {
          "type": "REPORT",
          "url": "https://ubuntu.com/security/CVE-2026-3886"
        },
        {
          "type": "REPORT",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-3886"
        }
      ],
      "related": [],
      "schema_version": "1.7.0",
      "severity": [
        {
          "score": "high",
          "type": "Ubuntu"
        }
      ],
      "upstream": [
        "CVE-2026-3886"
      ]
    }

    WID-SEC-W-2026-1855

    Vulnerability from csaf_certbund - Published: 2026-06-09 22:00 - Updated: 2026-09-09 22:00
    Summary
    QEMU: Schwachstelle ermöglicht Privilegieneskalation
    Severity
    Hoch
    Scope
    1 vulnerability in this advisory, including CVE-2026-3886.
    CVE-2026-3886
    Known affected: 3 products
    Open the full advisory