Back

MEDIUM

Qemu-kvm: heap off-by-one in kvm xen physdevop_map_pirq

Published Feb 18, 2026

Description

An off-by-one error was found in QEMU's KVM Xen guest support. A malicious guest could use this flaw to trigger out-of-bounds heap accesses in the QEMU process via the emulated Xen physdev hypercall interface, leading to a denial of service or potential memory corruption.

Affected products

Remediation

Red Hat statement

Xen guest support is disabled at build time in the `qemu-kvm` packages as shipped with Red Hat Enterprise Linux. Consequently, RHEL is not affected by this CVE.

References (5)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner fedora
Published Feb 18, 2026
Updated Feb 18, 2026
Reserved Jan 7, 2026

CISA Vulnrichment

Updated Feb 18, 2026

NVD

Status Deferred
Modified Jun 17, 2026

Red Hat

Severity Moderate
Public date Jan 9, 2026
Bugzilla 2428640

ENISA EUVD

Assigner fedora
Published Feb 18, 2026
Updated Feb 18, 2026

GitHub

No data