REDHAT-BUG-2401209: Use After Free

Published Oct 3, 2025
·
Updated

If the QIOChannelWebsock object is freed while it is waiting to complete a handshake, a GSource is leaked. This can lead to the callback firing later on and triggering a use-after-free in the use of the channel. This flaw can be abused by a malicious client with network access to the VNC WebSocket port to cause a denial of service during the WebSocket handshake prior to the VNC client authentication.

Reported-by: Grant Millar | Cylo <rid>

Upstream patch: https://lists.nongnu.org/archive/html/qemu-devel/2025-10/msg00786.html

Affected Software

1 affected component
Qemu Qemu

Event History

Oct 3, 2025
Data Sourced
via Red Hat·09:48 AM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-2401209?

The severity of REDHAT-BUG-2401209 is considered significant due to the potential for a use-after-free vulnerability.

2

How do I fix REDHAT-BUG-2401209?

Fixing REDHAT-BUG-2401209 involves applying the latest updates and patches provided by the QEMU project.

3

What are the consequences of REDHAT-BUG-2401209?

The consequences of REDHAT-BUG-2401209 can include denial of service or remote code execution if exploited by an attacker.

4

Who is affected by REDHAT-BUG-2401209?

Users of QEMU, particularly those utilizing the VNC WebSocket protocol, are affected by REDHAT-BUG-2401209.

5

Is there a workaround for REDHAT-BUG-2401209?

Currently, there are no confirmed workarounds for REDHAT-BUG-2401209 other than applying security updates.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203