REDHAT-BUG-2513498: Low severity Qemu Qemu vulnerability

Published Aug 10, 2026
·
Updated

QEMU's vhost inflight migration VMState handling uses a uint64t field for the destination buffer size, while the VMSVBUFFER load path reads the field as a signed int32t. On little-endian hosts, a crafted incoming migration state with bit 31 set can cause the negative value to be converted to a very large sizet. QEMU may then copy migration-stream data beyond the mmap-backed destination inflight region, causing a destination QEMU process crash or memory corruption. Exploitation requires control of the migration producer or write access to the migration channel and a configuration using vhost inflight migration.

Acknowledgments: Seungjung Kim (Kyonggi University)

Affected Software

1 affected component
Qemu Qemu

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Compensating control

    Prevent exploitation by not allowing attackers to gain control of the migration producer or write access to the migration channel, and avoid running a configuration that uses vhost inflight migration.

Event History

Aug 10, 2026
Data Sourced
via Red Hat·02:05 PM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-2513498?

The severity of REDHAT-BUG-2513498 is categorized as low.

2

What does REDHAT-BUG-2513498 describe?

REDHAT-BUG-2513498 describes an issue with QEMU's vhost inflight migration VMState handling related to type mismatches in buffer size representation.

3

How do I fix REDHAT-BUG-2513498?

To fix REDHAT-BUG-2513498, ensure you apply the latest patches provided by the QEMU development team that address this specific vulnerability.

4

What components are affected by REDHAT-BUG-2513498?

REDHAT-BUG-2513498 affects the QEMU virtualization software, specifically its vhost inflight migration handling.

5

What is the potential impact of REDHAT-BUG-2513498?

The potential impact of REDHAT-BUG-2513498 includes the risk of negative value conversions during migration on little-endian hosts, which could lead to instability or exploitation.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203