Impact
A flaw in QEMU’s cpu_physical_memory_map routine removes a guard that checks the mapped length, allowing a local attacker inside a guest virtual machine to write beyond the memory region allocated for that guest. This out‑of‑bounds write can corrupt heap objects or read protected guest memory that it is not authorized to access, potentially exposing sensitive data, violating data integrity, or triggering a denial of service within the guest environment. The weakness is classified as CWE‑787, an out‑of‑bounds write defect.
Affected Systems
The vulnerability affects Red Hat Enterprise Linux 6, 7, 8, 9 and 10 as well as Red Hat OpenShift Container Platform 4. These platforms run the QEMU hypervisor where the flaw occurs. No specific minor version ranges are listed, so all current releases of these distributions are considered vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, but the EPSS score of less than 1 % suggests a low probability of exploitation in the wild. The flaw is not listed in CISA’s KEV catalog. Exploitation requires the attacker to gain a foothold inside the guest; once the local privilege boundary is crossed, the memory corruption can affect guest memory, potentially leading to integrity violations or a denial of service within the guest environment. The description does not detail any impact on the host or other guests; any such impact is therefore inferred and not confirmed in the available data.
OpenCVE Enrichment
Ubuntu USN