CVE-2026-3842

A flaw was found in QEMU. This vulnerability allows a local attacker within a guest virtual machine to write data beyond its allocated memory. This occurs when cpu_physical_memory_map() returns a shorter length than expected, leading to an out-of-bounds write. Successful exploitation could result in unauthorized access to guest memory or corruption of heap-allocated objects, potentially causing information disclosure, data integrity issues, or a denial of service.
Configurations

No configuration.

History

No history.

Information

Published : 2026-07-16 01:16

Updated : 2026-09-01 13:19


NVD link : CVE-2026-3842

Mitre link : CVE-2026-3842

CVE.ORG link : CVE-2026-3842


JSON object : View

Products Affected

No product.

CWE
CWE-787

Out-of-bounds Write