CVE-2026-3195

A flaw was found in QEMU. When reading input audio in the virtio-snd device input callback, the `virtio_snd_pcm_in_cb` function did not check whether the iov could fit the data buffer, potentially leading to a heap out-of-bounds write. This issue exists due to an incomplete fix for CVE-2024-7730.
Configurations

No configuration.

History

No history.

Information

Published : 2026-06-19 17:16

Updated : 2026-09-01 13:19


NVD link : CVE-2026-3195

Mitre link : CVE-2026-3195

CVE.ORG link : CVE-2026-3195


JSON object : View

Products Affected

No product.

CWE
CWE-122

Heap-based Buffer Overflow