CVE-2026-48914: Red Hat Enterprise Linux 10

Medium severity, CVSS 6.7. EPSS: 0.2% chance of exploitation in the next 30 days.

A flaw was found in QEMU's virtio-blk device. The issue arises because the device does not properly validate the size of input descriptors before writing data. A malicious guest with high privileges could exploit this vulnerability by submitting a malformed virtio-blk SCSI request, leading to an out-of-bounds write in the host heap memory and a potential denial of service (DoS) for the QEMU process.

Affected products

  • Red Hat Red Hat Enterprise Linux 10: before 18:10.1.0-16.el10_2.5 (fixed in 18:10.1.0-16.el10_2.5)
  • Red Hat Red Hat Enterprise Linux 6
  • Red Hat Red Hat Enterprise Linux 7
  • Red Hat Red Hat Enterprise Linux 8
  • Red Hat Red Hat Enterprise Linux 9: before 17:10.1.0-17.el9_8.4 (fixed in 17:10.1.0-17.el9_8.4)
  • Red Hat Red Hat Enterprise Linux For NVIDIA 26
  • Red Hat Red Hat Openshift Container Platform 4

Published 2026-06-12. Last modified 2026-08-31.