Database/Kernel, userspace & hypervisor
QEMU (virtio): DMA reentrancy leads to double free across virtio devices - guest-to-host code execution in QEMU
CVSS 8.2CVE-2024-3446Kernel, userspace & hypervisorcurated
Impact
DMA reentrancy leads to double free across virtio devices - guest-to-host code execution in QEMU
Who can reach it
Tenant VM guest
What to do
QEMU update + VM restart or live-migration to patched hosts. GPU-passthrough VMs cannot be live-migrated, so this is a scheduled tenant-visible drain
References
Related entries
- Linux kernel (net/tls): A non-DATA record already copied out of the pending list could be merged with a second recordCVE-2024-58239 · Linux kernel (net/tls)High
- Intel ice driver (Ethernet 800 Series, Linux kernel mode): A missing check for an exceptional condition in theCVE-2025-20093 · Intel ice driver (Ethernet 800 Series, Linux kernel mode)High
- VMware ESXi: Arbitrary kernel write from the VMX process - sandbox escape completing the zero-day chainCVE-2025-22225 · VMware ESXiHigh
- OpenStack Nova: crafted QCOW header on a Flat-backend disk lets a tenant destroy host data on resizeCVE-2026-24708 · OpenStack Nova (Flat image backend, qemu-img resize)High
- Linux kernel (drivers/iommu/intel): A device that does not support ATS never gets inserted into the VT-d deviceCVE-2026-74355 · Linux kernel (drivers/iommu/intel)High
- Linux kernel (arch/x86/kvm/svm): If AVIC is inhibited while a nested guest is running, KVM leaves the x2APIC MSRsCVE-2026-74516 · Linux kernel (arch/x86/kvm/svm)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.