Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5049 articles · 189092 vulns · 37/41 feeds (7d)
← Back to list
4.4
CVE-2026-6426EXPLOITED
red hat · red hat enterprise linux

Qemu-kvm: vhost inflight migration vmstate integer type mismatch causes out-of-bounds access

Description

A type mismatch vulnerability was found in QEMU's vhost inflight migration VMState handling. The destination buffer size is stored as a uint64_t but read by the VMS_VBUFFER load path as a signed int32_t. On little-endian hosts, a crafted incoming migration state with bit 31 set causes the value to be interpreted as negative and then implicitly converted to a very large size_t, leading qemu_get_buffer() to copy migration-stream data beyond the bounds of the mmap-backed inflight region. This can result in a crash of the QEMU process or memory corruption. Exploitation requires control of the migration producer or write access to the migration channel, combined with a destination configured to use vhost inflight migration.

Affected Products

VendorProductVersions
red hatred hat enterprise linux—

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
open sourceopen source qemucert_advisory90%

References

  • https://access.redhat.com/security/cve/CVE-2026-6426(vdb-entry, x_refsource_REDHAT)
  • https://bugzilla.redhat.com/show_bug.cgi?id=2513498(issue-tracking, x_refsource_REDHAT)

Related News (2 articles)

Tier B
BSI Advisories1d ago
[NEU] [UNGEPATCHT] [mittel] QEMU: Schwachstelle ermöglicht Denial of Service
→ No new info (linked only)
Tier C
VulDB1d ago
CVE-2026-6426 | Red Hat QEMU VMState qemu_get_buffer memory corruption
→ No new info (linked only)
CVSS 3.14.4 MEDIUM
VectorCVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H
CISA KEV❌ No
Actively exploited✅ Yes
CWECWE-681
PublishedAug 10, 2026
Last enriched1d ago
Tags
remote code executionfile manipulationdenial of servicemultiple vulnerabilities
Trending Score45
Source articles2
Independent2
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-4480EXPKEV
Samba: samba: remote code execution in printing subsystem via unescaped job description
Trending: 48
NONECVE-2026-59091EXP
Gimp: gimp: multiple vulnerabilities in file format plugins via crafted image file
Trending: 46
NONECVE-2026-59090EXP
Gimp: gimp: arbitrary code execution in psd plugin due to unsigned underflow
Trending: 44
LOWCVE-2026-61477EXP
Libvirt: libvirt: newline injection in network xml dns txt/srv fields allows dnsmasq config directive injection
Trending: 43
NONECVE-2026-63623EXP
Libvirt: information disclosure via world-readable storage volume images during clone/convert
Trending: 42

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 10, 2026
Actively Exploited
Aug 10, 2026
Exploit Available
Aug 10, 2026
Discovered by ZDM
Aug 10, 2026