Vulnerability CVE-2025-14876: Information
Description
A flaw was found in the virtio-crypto device of QEMU. A malicious guest operating system can exploit a missing length limit in the AKCIPHER path, leading to uncontrolled memory allocation. This can result in a denial of service (DoS) on the host system by causing the QEMU process to terminate unexpectedly.
Severity: MEDIUM (5.5)
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Fixed packages
Package name | Branch | Fixed in version | Version from repository | Errata ID | Task # | State |
|---|---|---|---|---|---|---|
| qemu | sisyphus | 10.1.4-alt1 | 10.1.4-alt1 | ALT-PU-2026-3760-1 | 409502 | Fixed |
| qemu | sisyphus_riscv64 | 10.1.4-alt1 | 10.1.4-alt1 | ALT-PU-2026-3838-1 | - | Fixed |