CVE-2025-11234: Red Hat Enterprise Linux 10
High severity, CVSS 7.5. EPSS: 0.9% chance of exploitation in the next 30 days.
A flaw was found in QEMU. If the QIOChannelWebsock object is freed while it is waiting to complete a handshake, a GSource is leaked. This can lead to the callback firing later on and triggering a use-after-free in the use of the channel. This can be abused by a malicious client with network access to the VNC WebSocket port to cause a denial of service during the WebSocket handshake prior to the VNC client authentication.
Affected products
- Red Hat Red Hat Enterprise Linux 10: before 18:10.0.0-14.el10_1.5 (fixed in 18:10.0.0-14.el10_1.5)
- Red Hat Red Hat Enterprise Linux 6
- Red Hat Red Hat Enterprise Linux 7
- Red Hat Red Hat Enterprise Linux 8: before 8100020251120003312.489197e6 (fixed in 8100020251120003312.489197e6); before 8100020251202222937.489197e6 (fixed in 8100020251202222937.489197e6)
- Red Hat Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support: before 8040020260916092751.522a0ee4 (fixed in 8040020260916092751.522a0ee4)
- Red Hat Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On: before 8040020260916092751.522a0ee4 (fixed in 8040020260916092751.522a0ee4)
- Red Hat Red Hat Enterprise Linux 8.8 Telecommunications Update Service: before 8080020260910092120.63b34585 (fixed in 8080020260910092120.63b34585)
- Red Hat Red Hat Enterprise Linux 8.8 Update Services For SAP Solutions: before 8080020260910092120.63b34585 (fixed in 8080020260910092120.63b34585)
- Red Hat Red Hat Enterprise Linux 9: before 17:10.1.0-17.el9_8 (fixed in 17:10.1.0-17.el9_8)
- Red Hat Red Hat Enterprise Linux 9.0 Update Services For SAP Solutions: before 17:6.2.0-11.el9_0.10 (fixed in 17:6.2.0-11.el9_0.10)
- Red Hat Red Hat Enterprise Linux 9.2 Update Services For SAP Solutions: before 17:7.2.0-14.el9_2.24 (fixed in 17:7.2.0-14.el9_2.24)
- Red Hat Red Hat Enterprise Linux 9.4 Extended Update Support: before 17:8.2.0-11.el9_4.18 (fixed in 17:8.2.0-11.el9_4.18); before 17:8.2.0-11.el9_4.19 (fixed in 17:8.2.0-11.el9_4.19)
- Red Hat Red Hat Openshift Container Platform 4.12: before 412.86.202608241157-0 (fixed in 412.86.202608241157-0)
- Red Hat Red Hat Openshift Container Platform 4.16: before 416.94.202601071926-0 (fixed in 416.94.202601071926-0)
- Red Hat Red Hat Openshift Container Platform 4.17: before 417.94.202601120213-0 (fixed in 417.94.202601120213-0)
- Red Hat Red Hat Openshift Container Platform 4.18: before 418.94.202601071817-0 (fixed in 418.94.202601071817-0)
Published 2025-10-03. Last modified 2026-10-10.