CVE-2026-3195
Red Hat Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7
A flaw was found in QEMU. When reading input audio in the virtio-snd device input callback, the `virtio_snd_pcm_in_cb` function did not check whether the iov could fit the data buffer, potentially leading to a heap out-of-bounds write. This issue exists due to an incomplete fix for CVE-2024-7730.
- CVSS
- 7.4
- EPSS
- 0.17% 6.77% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.20