{"cvss":6.7,"datePublished":"2026-06-12T10:16:22.177","dateUpdated":"2026-08-31T18:17:17.337","description":"A flaw was found in QEMU's virtio-blk device. The issue arises because the device does not properly validate the size of input descriptors before writing data. A malicious guest with high privileges could exploit this vulnerability by submitting a malformed virtio-blk SCSI request, leading to an out-of-bounds write in the host heap memory and a potential denial of service (DoS) for the QEMU process.","id":"CVE-2026-48914","raw":{"affected":[{"affectedData":[{"collectionURL":"https://gitlab.com/qemu-project/qemu","defaultStatus":"unaffected","packageName":"qemu","versions":[{"lessThanOrEqual":"11.0.1","status":"affected","version":"1.1.0","versionType":"semver"}]},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/o:redhat:enterprise_linux:10.2"],"defaultStatus":"affected","packageName":"qemu-kvm","product":"Red Hat Enterprise Linux 10","vendor":"Red Hat","versions":[{"lessThan":"*","status":"unaffected","version":"18:10.1.0-16.el10_2.5","versionType":"rpm"}]},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:enterprise_linux:9::appstream"],"defaultStatus":"affected","packageName":"qemu-kvm","product":"Red Hat Enterprise Linux 9","vendor":"Red Hat","versions":[{"lessThan":"*","status":"unaffected","version":"17:10.1.0-17.el9_8.4","versionType":"rpm"}]},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/o:redhat:enterprise_linux:6"],"defaultStatus":"unknown","packageName":"qemu-kvm","product":"Red Hat Enterprise Linux 6","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/o:redhat:enterprise_linux:7"],"defaultStatus":"unknown","packageName":"qemu-kvm","product":"Red Hat Enterprise Linux 7","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/o:redhat:enterprise_linux:7"],"defaultStatus":"unknown","packageName":"qemu-kvm-ma","product":"Red Hat Enterprise Linux 7","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/o:redhat:enterprise_linux:8"],"defaultStatus":"affected","packageName":"virt:rhel/qemu-kvm","product":"Red Hat Enterprise Linux 8","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:enterprise_linux_nvidia:"],"defaultStatus":"affected","packageName":"qemu-kvm","product":"Red Hat Enterprise Linux for NVIDIA 26","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:openshift:4"],"defaultStatus":"affected","packageName":"openshift/ose-rhel-coreos-8","product":"Red Hat OpenShift Container Platform 4","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:openshift:4"],"defaultStatus":"affected","packageName":"openshift/ose-rhel-coreos-9","product":"Red Hat OpenShift Container Platform 4","vendor":"Red Hat"}],"source":"secalert@redhat.com"}],"cveTags":[],"descriptions":[{"lang":"en","value":"A flaw was found in QEMU's virtio-blk device. The issue arises because the device does not properly validate the size of input descriptors before writing data. A malicious guest with high privileges could exploit this vulnerability by submitting a malformed virtio-blk SCSI request, leading to an out-of-bounds write in the host heap memory and a potential denial of service (DoS) for the QEMU process."}],"id":"CVE-2026-48914","lastModified":"2026-08-31T18:17:17.337","metrics":{"cvssMetricV31":[{"cvssData":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"HIGH","baseScore":6.7,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"LOW","privilegesRequired":"HIGH","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:H","version":"3.1"},"exploitabilityScore":1.5,"impactScore":4.7,"source":"secalert@redhat.com","type":"Secondary"}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"id":"CVE-2026-48914","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-06-12T09:57:24.232821Z","version":"2.0.3"}}]},"published":"2026-06-12T10:16:22.177","references":[{"source":"secalert@redhat.com","url":"https://access.redhat.com/errata/RHSA-2026:39311"},{"source":"secalert@redhat.com","url":"https://access.redhat.com/errata/RHSA-2026:58571"},{"source":"secalert@redhat.com","url":"https://access.redhat.com/security/cve/CVE-2026-48914"},{"source":"secalert@redhat.com","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2488283"},{"source":"secalert@redhat.com","url":"https://lore.kernel.org/qemu-devel/20260526154957.1741622-1-stefanha@redhat.com/"}],"sourceIdentifier":"secalert@redhat.com","vulnStatus":"Awaiting Analysis","weaknesses":[{"description":[{"lang":"en","value":"CWE-122"}],"source":"secalert@redhat.com","type":"Secondary"}]},"severity":"MEDIUM","source":"nvd","title":"A flaw was found in QEMU's virtio-blk device"}