An integer overflow vulnerability was found in the virtio-snd device via PCM_INFO requests from the guest. A malicious guest can provide out-of-bounds stream counts, potentially leading to unbounded memory allocation on the host and a denial of service condition.

Project Subscriptions

Vendors Products
Enterprise Linux Subscribe
Openshift Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 19 Jun 2026 18:15:00 +0000

Type Values Removed Values Added
Title qemu-kvm: virtio-snd: integer overflow leading to unbounded memory allocation Qemu-kvm: virtio-snd: integer overflow leading to unbounded memory allocation
First Time appeared Redhat
Redhat enterprise Linux
Redhat openshift
CPEs cpe:/a:redhat:openshift:4
cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
Redhat openshift
References

Wed, 04 Mar 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Qemu
Qemu qemu
Vendors & Products Qemu
Qemu qemu

Tue, 03 Mar 2026 00:15:00 +0000

Type Values Removed Values Added
Description An integer overflow vulnerability was found in the virtio-snd device via PCM_INFO requests from the guest. A malicious guest can provide out-of-bounds stream counts, potentially leading to unbounded memory allocation on the host and a denial of service condition.
Title qemu-kvm: virtio-snd: integer overflow leading to unbounded memory allocation
Weaknesses CWE-190
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: fedora

Published:

Updated: 2026-06-19T16:23:02.849Z

Reserved: 2026-02-25T11:09:37.726Z

Link: CVE-2026-3196

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-02-20T00:00:00Z

Links: CVE-2026-3196 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-03-04T21:04:37Z

Weaknesses