REDHAT-BUG-2458150: High severity Qemu Qemu vulnerability
If cpuphysicalmemorymap() returns a length shorter than the one that was passed into the function, writing the full outlen bytes causes an access beyond the memory allocated to the guest; or in the case of the MMIO bounce buffer, an out-of-bounds access in a heap-allocated object.
Upstream fix: https://gitlab.com/qemu-project/qemu/-/commit/4f28b87fdd24df2049626106b7c24d0180952115
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Apply the upstream QEMU commit fix referenced (4f28b87fdd24df2049626106b7c24d0180952115) to prevent an out-of-bounds access in cpu_physical_memory_map() handling when it returns a shorter length than out_len.
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2458150?
The severity of REDHAT-BUG-2458150 is high with a rating of 7.
How do I fix REDHAT-BUG-2458150?
To fix REDHAT-BUG-2458150, apply the upstream patch provided in the recent QEMU updates.
What risks are associated with REDHAT-BUG-2458150?
REDHAT-BUG-2458150 presents a risk of memory corruption resulting in out-of-bounds access.
Which software is affected by REDHAT-BUG-2458150?
The software affected by REDHAT-BUG-2458150 is QEMU.
When was REDHAT-BUG-2458150 published?
REDHAT-BUG-2458150 was published on April 14, 2026.