7.8 HIGH
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Local (L)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): Low (L)
- User Interaction (UI): None (N)
- Scope (S): Unchanged (U)
- Confidentiality (C): High (H)
- Integrity (I): High (H)
- Availability (A): High (H)
- Modified Attack Vector (MAV): Local (L)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): High (H)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): High (H)
- Modified Availability (MA): High (H)
by @symphorien Activity log
- Created suggestion
- @symphorien dismissed
Qemu-kvm: hyperv/syndbg: missing mapped-length guard after cpu_physical_memory_map causes host oob write
A flaw was found in QEMU. This vulnerability allows a local attacker within a guest virtual machine to write data beyond its allocated memory. This occurs when cpu_physical_memory_map() returns a shorter length than expected, leading to an out-of-bounds write. Successful exploitation could result in unauthorized access to guest memory or corruption of heap-allocated objects, potentially causing information disclosure, data integrity issues, or a denial of service.
References
Affected products
- <11.0.0
Matching in nixpkgs
pkgs.qemu
Generic and open source machine emulator and virtualizer
pkgs.qemu_kvm
Generic and open source machine emulator and virtualizer
pkgs.qemu_xen
Generic and open source machine emulator and virtualizer
pkgs.qemu-user
QEMU User space emulator - launch executables compiled for one CPU on another CPU
pkgs.qemu_full
Generic and open source machine emulator and virtualizer
pkgs.qemu_test
Generic and open source machine emulator and virtualizer
pkgs.qemu-utils
Generic and open source machine emulator and virtualizer
pkgs.canokey-qemu
CanoKey QEMU Virtual Card
-
nixos-unstable 0-unstable-2026-03-24
- nixpkgs-unstable 0-unstable-2026-03-24
- nixos-unstable-small 0-unstable-2026-03-24
-
nixos-26.05 0-unstable-2026-03-24
- nixos-26.05-small 0-unstable-2026-03-24
- nixpkgs-26.05-darwin 0-unstable-2026-03-24
pkgs.ubootQemuX86
Boot loader for embedded systems
pkgs.ubootQemuX86_64
Boot loader for embedded systems
pkgs.ubootQemuAarch64
Boot loader for embedded systems
pkgs.qemu-python-utils
Python tooling used by the QEMU project to build, configure, and test QEMU
pkgs.armTrustedFirmwareQemu
Reference implementation of secure world software for ARMv8-A
pkgs.python313Packages.qemu
Python tooling used by the QEMU project to build, configure, and test QEMU
pkgs.python314Packages.qemu
Python tooling used by the QEMU project to build, configure, and test QEMU
pkgs.python313Packages.qemu-qmp
Asyncio library for communicating with QEMU Monitor Protocol (“QMP”) servers
Package maintainers
-
@lopsided98 Ben Wolsieffer <benwolsieffer@gmail.com>
-
@symphorien Guillaume Girol <symphorien_nixpkgs@xlumurb.eu>
-
@devplayer0 Jack O'Sullivan <dev@nul.ie>
-
@DavHau David Hauer <d.hauer.it@gmail.com>
-
@brianmcgillion Brian McGillion <bmg.avoin@gmail.com>
-
@alyssais Alyssa Ross <hi@alyssa.is>
-
@SigmaSquadron Fernando Rodrigues <alpha@sigmasquadron.net>
-
@hehongbo Hongbo
-
@CertainLach Yaroslav Bolyukin <iam@lach.pw>