Threats Tagged 'cve-2025-14876'
View all threats tagged with 'cve-2025-14876'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2025-14876'
Click on any threat for detailed analysis and mitigation recommendations
0 This update for qemu fixes the following issues: - CVE-2025-14876: qemu-kvm: Unbounded allocation in virtio-crypto (bsc#1255400). - CVE-2026-0665: out-of-bounds heap access can lead to a denial of service or potential memory corruption (bsc#1256484). - CVE-2026-2243: incorrect bounds check leads to heap out-of-bounds read and a 12-byte information leak when processing specially crafted VMDK files (bsc#1258509). - CVE-2026-3195: heap buffer overflow when reading input audio in the virtio-snd device input callback due to insufficient checks in `virtio_snd_pcm_in_cb` (bsc#1259080). - CVE-2026-3196: integer overflow in the virtio-snd device via PCM_INFO requests from the guest leads to unbounded memory allocation and host denial-of-service (bsc#1259079). - CVE-2026-3842: hyperv/syndbg: missing mapped-length guard after cpu_physical_memory_map causes host OOB write (bsc#1262089). Join the discussion | GCVE Database | 06/12/2026, 13:54:09 UTC Added: 06/13/2026, 10:23:24 UTC |
CVE-2025-14876 is a vulnerability in the virtio-crypto device of QEMU version 7.1.0 where a missing length limit in the AKCIPHER path allows a malicious guest OS to trigger uncontrolled memory allocation. This flaw can cause the QEMU process on the host to terminate unexpectedly, resulting in a denial of service (DoS). The vulnerability has a CVSS score of 5.5, indicating medium severity. No known exploits are reported in the wild. There is no explicit vendor advisory content confirming a patch or mitigation status. Join the discussion | CVE Database V5 | 02/18/2026, 20:47:54 UTC Added: 02/18/2026, 21:11:15 UTC |
Showing 1 to 2 of 2 results