Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 0.2%top 93%

CVE-2026-3195: Heap-based Buffer Overflow

0
High
Published: 06/19/2026 (06/19/2026, 16:23:57 UTC)
Source: GCVE Database

Description

CVE-2026-3195 is a heap-based buffer overflow vulnerability in QEMU's virtio-snd device input callback function, virtio_snd_pcm_in_cb. The flaw arises from insufficient validation of input audio data buffer sizes, potentially leading to out-of-bounds heap writes. This vulnerability is a result of an incomplete fix for a previous issue (CVE-2024-7730). It affects multiple Ubuntu package versions and is rated with a high severity CVSS score of 7.4. The vulnerability could allow an attacker inside a guest virtual machine to cause a denial of service or possibly execute arbitrary code on the host. Red Hat's QEMU packages are not affected due to the virtio-snd device being disabled at build time. Official patches are available from Ubuntu, and system updates followed by QEMU virtual machine restarts are required to remediate the issue.

CVSS v3.1

Score 7.4high

Attack Vector
Local
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected software

Ubuntu:24.04:LTSmore threats →ghsa
qemu
pkg:deb/ubuntu/qemu?arch=source&distro=noble
Affected versions
<1:8.2.2+ds-0ubuntu1.16=1:8.0.4+dfsg-1ubuntu3=1:8.0.4+dfsg-1ubuntu4=1:8.0.4+dfsg-1ubuntu5=1:8.1.3+ds-1ubuntu2=1:8.2.1+ds-1ubuntu1=1:8.2.1+ds-1ubuntu8=1:8.2.1+ds-1ubuntu9=1:8.2.2+ds-0ubuntu1=1:8.2.2+ds-0ubuntu1.2=1:8.2.2+ds-0ubuntu1.4=1:8.2.2+ds-0ubuntu1.5=1:8.2.2+ds-0ubuntu1.6=1:8.2.2+ds-0ubuntu1.7=1:8.2.2+ds-0ubuntu1.8=1:8.2.2+ds-0ubuntu1.9=1:8.2.2+ds-0ubuntu1.10=1:8.2.2+ds-0ubuntu1.11=1:8.2.2+ds-0ubuntu1.12=1:8.2.2+ds-0ubuntu1.13=1:8.2.2+ds-0ubuntu1.14=1:8.2.2+ds-0ubuntu1.15
Ubuntu:25.10more threats →ghsa
qemu
pkg:deb/ubuntu/qemu?arch=source&distro=questing
Affected versions
<1:10.1.0+ds-5ubuntu2.6=1:9.2.1+ds-1ubuntu5=1:10.0.2+ds-1ubuntu1=1:10.0.2+ds-1ubuntu2=1:10.1.0+ds-1ubuntu1=1:10.1.0+ds-5ubuntu1=1:10.1.0+ds-5ubuntu2=1:10.1.0+ds-5ubuntu2.1=1:10.1.0+ds-5ubuntu2.2=1:10.1.0+ds-5ubuntu2.4=1:10.1.0+ds-5ubuntu2.5
Ubuntu:26.04:LTSmore threats →ghsa
qemu
pkg:deb/ubuntu/qemu?arch=source&distro=resolute
Affected versions
=1:10.1.0+ds-5ubuntu2=1:10.1.0+ds-5ubuntu3=1:10.1.0+ds-5ubuntu4=1:10.1.0+ds-5ubuntu5=1:10.2.1+ds-1ubuntu1=1:10.2.1+ds-1ubuntu2=1:10.2.1+ds-1ubuntu3=1:10.2.1+ds-1ubuntu3.1=1:10.2.1+ds-1ubuntu3.2

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/21/2026, 16:55:53 UTC

Technical Analysis

A heap-based buffer overflow vulnerability (CWE-122) exists in QEMU's virtio-snd device input callback function, virtio_snd_pcm_in_cb, due to lack of proper bounds checking on the input audio data buffer (iov). This flaw can lead to heap out-of-bounds writes, potentially allowing an attacker with local access inside a guest VM to crash QEMU or execute arbitrary code on the host. The vulnerability is linked to an incomplete fix for CVE-2024-7730. It affects various Ubuntu QEMU package versions, specifically in Ubuntu 24.04 LTS and 25.10 releases. Red Hat Enterprise Linux's QEMU packages are not affected because the virtio-snd device is disabled at build time, removing the attack surface. The CVSS v3.1 score is 7.4 (High), with attack vector local, high attack complexity, no privileges required, no user interaction, and high impact on confidentiality, integrity, and availability. Official Ubuntu advisories provide patched package versions and recommend restarting all QEMU virtual machines after updating.

Potential Impact

An attacker with local access inside a guest virtual machine could exploit this vulnerability to cause QEMU to crash (denial of service) or potentially execute arbitrary code on the host system. The vulnerability impacts confidentiality, integrity, and availability of the host running QEMU. The CVSS score of 7.4 reflects a high severity with significant potential impact. Red Hat's QEMU packages are not affected due to the virtio-snd device being disabled at build time, effectively mitigating the risk in those environments.

Mitigation Recommendations

Apply the official patches provided by Ubuntu by updating to the fixed package versions listed in the Ubuntu security advisory USN-8161-1. After updating, restart all QEMU virtual machines to ensure the fixes take effect. For Red Hat Enterprise Linux users, no action is required as the virtio-snd device is disabled at build time, removing the attack surface for this vulnerability.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
UBUNTU-CVE-2026-3195
Osv Schema Version
1.7.0
Aliases
[]
Ecosystems
["Ubuntu:24.04:LTS","Ubuntu:25.10","Ubuntu:26.04:LTS"]
Database Specific Severity
null
Cvss Version
3.1

Threat ID: 6a74cf9ebf8831d5391b043b

Added to database: 08/06/2026, 18:17:02 UTC

Last enriched: 08/21/2026, 16:55:53 UTC

Last updated: 08/21/2026, 22:52:12 UTC

Views: 11

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses