Database/Kernel, userspace & hypervisor
QEMU: use-after-free in the VNC WebSocket handshake crashes the VM process before client authentication
Impact
If the QIOChannelWebsock object is freed while a handshake is still pending, its GSource is leaked and the callback fires later against freed memory. A client that can open the VNC WebSocket port can trigger this during the handshake, before VNC authentication runs, and take down the QEMU process. On a virtualized GPU node that is the whole guest: a VM with passthrough or vGPU devices dies with its training or inference job, and device reset and reattach on restart is not always clean. The exposure is denial of service - the record does not claim code execution.
Who can reach it
Anyone with network reach to the VNC WebSocket port of a running guest. No authentication needed - the crash happens before the VNC client authenticates, so any exposed or management-VLAN-reachable VNC WebSocket listener is enough.
What to do
Install the patched qemu-kvm from the Red Hat errata for your release (RHSA-2025:23228, RHSA-2026:0326, RHSA-2026:0332, RHSA-2026:0702, RHSA-2026:1831 across RHEL 8/9/10 and OCP 4.16). Running guests keep the old binary, so each VM must be stopped and restarted (or live-migrated where the GPU topology allows it) - budget a drain of the affected hypervisors. Mitigation in the meantime: disable the VNC websocket option or firewall the VNC WebSocket port to the management network only.
References
Related entries
- Linux kernel (net/tls): If a page allocation fails while the TLS strparser is copying a partial record, the receiveCVE-2025-38018 · Linux kernel (net/tls)High
- Linux kernel (drivers/nvme/target): A connecting client that abandons the TCP connection at the right moment duringCVE-2025-38035 · Linux kernel (drivers/nvme/target)High
- Linux kernel (net/xfrm): Several error paths in the ESP-in-TCP receive code return without freeing the skb, soCVE-2025-38057 · Linux kernel (net/xfrm)High
- Linux kernel (drivers/nvme/target): Every command a client sends to the target carrying metadata (protectionCVE-2025-38405 · Linux kernel (drivers/nvme/target)High
- Linux kernel mlx5_core IPsec RX offload: When hardware reports an xfrm state ID for a decrypted packet whose stateCVE-2025-38590 · Linux kernel mlx5_core IPsec RX offloadHigh
- Linux kernel (net/xfrm): Xfrm_alloc_spi could hand out an SPI that is already in use by another inbound SA, because theCVE-2025-39797 · Linux kernel (net/xfrm)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.