CVE-2026-2243: Qemu-kvm: heap buffer out-of-bounds read in vmdk compressed grain parsing
A flaw was found in QEMU. A specially crafted VMDK image could trigger an out-of-bounds read vulnerability, potentially leading to a 12-byte leak of sensitive information or a denial of service condition (DoS).
Other sources
A heap buffer over-read was found in block/vmdk.c. A crafted VMDK file can make qemu-img (or qemu with vmdk disk) read past an allocated buffer, potentially leading to a 12-byte information leak or denial of service.
Patch: https://lore.kernel.org/qemu-devel/CAJ9qJssSwxkmEVethg57-Ph6maEfButSaV-r07ma9x1sp6wYg@mail.gmail.com/
Credit: Halil Oktay (oblivionsage)
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2243?
CVE-2026-2243 is considered a moderate severity vulnerability due to its potential to leak sensitive information and cause denial of service.
How do I fix CVE-2026-2243?
To fix CVE-2026-2243, upgrade to the latest version of QEMU where this vulnerability has been patched.
What type of vulnerability is CVE-2026-2243?
CVE-2026-2243 is an out-of-bounds read vulnerability affecting the handling of specially crafted VMDK images.
What are the potential impacts of CVE-2026-2243?
The impacts of CVE-2026-2243 include a 12-byte leak of sensitive information and possible denial of service conditions.
Which software is affected by CVE-2026-2243?
CVE-2026-2243 affects the QEMU virtualization software.