CVE-2026-3842: Qemu-kvm: hyperv/syndbg: missing mapped-length guard after cpu_physical_memory_map causes host oob write

Published Apr 14, 2026
·
Updated

A flaw was found in QEMU. This vulnerability allows a local attacker within a guest virtual machine to write data beyond its allocated memory. This occurs when cpuphysicalmemorymap() returns a shorter length than expected, leading to an out-of-bounds write. Successful exploitation could result in unauthorized access to guest memory or corruption of heap-allocated objects, potentially causing information disclosure, data integrity issues, or a denial of service.

Other sources

If cpuphysicalmemorymap() returns a length shorter than the one that was passed into the function, writing the full outlen bytes causes an access beyond the memory allocated to the guest; or in the case of the MMIO bounce buffer, an out-of-bounds access in a heap-allocated object.

Upstream fix: https://gitlab.com/qemu-project/qemu/-/commit/4f28b87fdd24df2049626106b7c24d0180952115

Red Hat

Qemu-kvm: hyperv/syndbg: missing mapped-length guard after cpuphysicalmemorymap causes host oob write

Microsoft

Affected Software

2 affected componentsFixes available
Qemu Qemu
Microsoft azl3 qemu 9.1.0-10<9.1.0-11
9.1.0-11

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 9.1.0-11
  2. Compensating control

    Apply the upstream QEMU fix referenced by commit 4f28b87fdd24df2049626106b7c24d0180952115 to ensure hyperv/syndbg uses a mapped-length guard after cpu_physical_memory_map() so out_len is not written when the returned length is shorter than expected.

Event History

Apr 14, 2026
Data Sourced
via Red Hat·07:34 AM
DescriptionSeverityAffected Software
Jul 16, 2026
CVE Published
via MITRE·12:20 AM
Data Sourced
via MITRE·12:20 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:16 AM
DescriptionSeverityWeakness
Jul 19, 2026
Data Sourced
via Microsoft·08:02 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·08:02 AM
DescriptionSeverity
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-3842?

CVE-2026-3842 has a severity rating of high with a CVSS score of 7.8.

2

How do I fix CVE-2026-3842?

To fix CVE-2026-3842, update QEMU to the latest version that addresses this vulnerability.

3

Who is impacted by CVE-2026-3842?

CVE-2026-3842 impacts local users within guest virtual machines running vulnerable versions of QEMU.

4

What can happen if CVE-2026-3842 is exploited?

Exploiting CVE-2026-3842 can lead to out-of-bounds writes, potentially allowing attackers to overwrite memory and escalate privileges.

5

When was CVE-2026-3842 published?

CVE-2026-3842 was published on April 14, 2026.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203