A flaw was found in QEMU. When reading input audio in the virtio-snd device input callback, the `virtio_snd_pcm_in_cb` function did not check whether the iov could fit the data buffer, potentially leading to a heap out-of-bounds write. This issue exists due to an incomplete fix for CVE-2024-7730.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-06-19 17:16
Updated : 2026-09-01 13:19
NVD link : CVE-2026-3195
Mitre link : CVE-2026-3195
CVE.ORG link : CVE-2026-3195
JSON object : View
Products Affected
No product.
CWE
CWE-122
Heap-based Buffer Overflow
