CVE-2024-26328: Qemu

Medium severity, CVSS 6.0. EPSS: 0.3% chance of exploitation in the next 30 days.

An issue was discovered in QEMU 7.1.0 through 8.2.1. register_vfs in hw/pci/pcie_sriov.c does not set NumVFs to PCI_SRIOV_TOTAL_VF, and thus interaction with hw/nvme/ctrl.c is mishandled.

Affected products

  • Qemu Qemu: from 7.1.0, up to and including 8.2.1

Published 2024-02-19. Last modified 2026-06-17.