CVE-2024-26327: Qemu

Medium severity, CVSS 5.3. EPSS: 0.6% chance of exploitation in the next 30 days.

An issue was discovered in QEMU 7.1.0 through 8.2.1. register_vfs in hw/pci/pcie_sriov.c mishandles the situation where a guest writes NumVFs greater than TotalVFs, leading to a buffer overflow in VF implementations.

Affected products

  • Qemu Qemu: from 7.1.0, up to and including 8.2.1

Published 2024-02-19. Last modified 2026-06-17.