CVE-2026-3196: Qemu-kvm: virtio-snd: integer overflow leading to unbounded memory allocation
An integer overflow vulnerability was found in the virtio-snd device via PCMINFO requests from the guest. A malicious guest can provide out-of-bounds stream counts, potentially leading to unbounded memory allocation on the host and a denial of service condition.
Other sources
Qemu-kvm: virtio-snd: integer overflow leading to unbounded memory allocation
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 9.1.0-10
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3196?
CVE-2026-3196 has a medium severity score of 5.5.
What impact does CVE-2026-3196 have?
CVE-2026-3196 can lead to unbounded memory allocation, causing a denial of service condition.
How can I mitigate CVE-2026-3196?
To mitigate CVE-2026-3196, ensure you are running the latest version of QEMU that addresses this vulnerability.
What systems are affected by CVE-2026-3196?
CVE-2026-3196 affects environments using QEMU-KVM with the virtio-snd device.
What type of vulnerability is CVE-2026-3196?
CVE-2026-3196 is classified as an integer overflow vulnerability.