Back

MEDIUM

Qemu-kvm: virtio-snd: integer overflow leading to unbounded memory allocation

Published Jun 19, 2026

Description

An integer overflow vulnerability was found in the virtio-snd device via PCM_INFO requests from the guest. A malicious guest can provide out-of-bounds stream counts, potentially leading to unbounded memory allocation on the host and a denial of service condition.

Affected products

Remediation

Red Hat statement

The `qemu-kvm` packages as shipped with Red Hat Enterprise Linux are not affected by this CVE. The virtio-snd device is disabled at build-time in RHEL, effectively removing the attack surface.

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner fedora
Published Jun 19, 2026
Updated Jun 22, 2026
Reserved Feb 25, 2026
CISA Vulnrichment
Updated Jun 22, 2026
NVD
Status Awaiting Analysis
Modified Jun 22, 2026
Red Hat
Severity Moderate
Public date Feb 20, 2026
ENISA EUVD
Assigner n/a
Published n/a
Updated n/a
Exploited since n/a
Link n/a