关键漏洞信息 漏洞编号: 2440934 (CVE-2026-2243) 标题: qemu-kvm: Heap buffer out-of-bounds read in VMDK compressed grain parsing 状态: NEW 产品: Security Response 组件: vulnerability 版本: unspecified 硬件: All 操作系统: Linux 优先级: low 严重性: low 报告日期: 2026-02-19 11:38 UTC 修改日期: 2026-02-19 17:39 UTC 漏洞描述 描述: A heap buffer over-read was found in block/vmdk.c. A crafted VMDK file can make qemu-img (or qemu with vmdk disk) read past an allocated buffer, potentially leading to a 12-byte information leak or denial of service. 补丁: https://lore.kernel.org/qemu-devel/CAJ9qJssSwxkmEVethg57-Ph6maEfButSaV-r07ma9_x1sp6wYg@mail.gmail.com/ Credit: Halil Oktay (oblivionsage)