Impact
A type mismatch in QEMU’s vhost inflight migration VMState handling allows a negative 32‑bit size to be interpreted as a very large unsigned size_t, which causes an out‑of‑bounds copy into an mmap‑backed region. This can corrupt memory or crash the QEMU process, potentially compromising the stability of virtual machines.
Affected Systems
RHEL 6, 7, 8, 9, and 10; RHEL for NVIDIA 26; Red Hat OpenShift Container Platform 4 – all affected when vhost inflight migration is enabled.
Risk and Exploitability
The vulnerability scores a CVSS of 4.4 and has no EPSS data, and it is not listed in KEV. An attacker must control the migration producer or write to the migration channel and must have a destination configured for vhost inflight migration. These conditions limit the attack surface, resulting in a moderate overall risk of crash or memory corruption rather than immediate remote code execution.
OpenCVE Enrichment