Database/Kernel, userspace & hypervisor
QEMU e1000: guest-triggered stack overflow in the loopback receive path crashes the host QEMU process
Impact
A user inside a guest can drive the emulated e1000 device into loopback mode with a short frame and overrun a stack buffer in the host QEMU process. The advisory claims denial of service only: the QEMU process dies, taking that VM with it. On a virtualized GPU cloud that means a tenant can reliably kill their own instance and, more importantly, exercise a memory-corruption path in the process that owns the passthrough GPU and the VFIO mappings for that node. Only guests configured with the e1000 NIC model are reachable; virtio-net guests are not affected by this path.
Who can reach it
Any authenticated user inside a guest VM that has an emulated e1000 NIC. No host access and no special guest privilege beyond the ability to configure the interface is described in the record.
What to do
Apply the distro QEMU update (Red Hat tracks it per RHEL 6 through 10 and OpenShift Container Platform 4; the record does not name fixed package versions, so check the vendor page for your stream). Running guests keep the old QEMU binary in memory, so the fix only lands after each VM is live-migrated off and restarted or stopped and started, which on a GPU host means draining tenant workloads. Interim mitigation without a restart window: move affected guests to virtio-net instead of the e1000 model.
References
Related entries
- Linux kernel (drivers/iommu): The ARM long-descriptor unmap path returns a negative errno through an unsigned size_tCVE-2026-23067 · Linux kernel (drivers/iommu)Medium
- Linux kernel (drivers/pci): Tearing down a PF that still has SR-IOV VFs takes pci_rescan_remove_lock recursively andCVE-2026-43147 · Linux kernel (drivers/pci)Medium
- Linux kernel (drivers/iommu/iommufd): A failed copy_to_user while draining the iommufd fault queue restarts the sameCVE-2026-64290 · Linux kernel (drivers/iommu/iommufd)Medium
- Linux kernel (drivers/vfio): A blocked migration-state transition makes the vfio state machine spin forever whileCVE-2026-64474 · Linux kernel (drivers/vfio)Medium
- Intel CPU (MMIO Stale Data / SBDR): Incomplete cleanup of multi-core shared buffers - stale data read across domainsCVE-2022-21123 · Intel CPU (MMIO Stale Data / SBDR)Medium
- Linux kernel (drivers/vfio/platform): A tenant holding a vfio-platform device can loopback-trigger an interrupt beforeCVE-2024-26813 · Linux kernel (drivers/vfio/platform)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.