Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

QEMU — Vulnerabilities & Security Advisories 77

All 77 CVE vulnerabilities found in QEMU, with AI-generated Chinese analysis, references, and POCs.

This page presents vulnerability aggregation data for the QEMU product, focusing on common weakness enumerations managed by its vendor, Red Hat and the QEMU project maintainers. It compiles a comprehensive list of security defects, ranging from buffer overflows and use-after-free errors to logic flaws and input validation issues, covering reported incidents from the initial release through recent updates in the current decade. Users can leverage this resource to track vendor-specific advisories and patch notes as they are released, gain a deeper understanding of the structural weaknesses inherent in virtualization software, and examine the historical timeline of vulnerabilities affecting this specific hypervisor to assess long-term risk patterns. The aggregation ensures that developers, security analysts, and system administrators have a centralized view of the security posture of QEMU without needing to cross-reference multiple disparate sources. By organizing these entries chronologically and categorizing them by severity and type, the page facilitates efficient remediation planning and compliance auditing. Readers can identify recurring vulnerability classes that may indicate systemic design issues, compare the frequency of critical flaws against minor issues, and monitor the response time of the maintainers in addressing disclosed security concerns. This approach supports informed decision-making regarding upgrade schedules and mitigation strategies for environments relying on QEMU for virtualization tasks.

Vendor: qemu

CVE IDTitleCVSSSeverityPublished
CVE-2025-54566 QEMU 安全漏洞 CWE-642 4.2 Medium2025-07-25
CVE-2025-54567 QEMU 安全漏洞 CWE-684 4.2 Medium2025-07-25
CVE-2023-2680 Dma reentrancy issue (incomplete fix for cve-2021-3750) CWE-416 7.5 High2023-09-13
CVE-2023-3301 Triggerable assertion due to race condition in hot-unplug CWE-617 5.6 Medium2023-09-13
CVE-2023-3180 Heap buffer overflow in virtio_crypto_sym_op_helper() CWE-122 6.0 Medium2023-08-03
CVE-2023-1386 Qemu: 9pfs: suid/sgid bits not dropped on file write CWE-281 3.3 Low2023-07-24
CVE-2023-3354 Improper i/o watch removal in tls handshake can lead to remote unauthenticated denial of service CWE-476 7.5 High2023-07-11
CVE-2023-0664 QEMU Guest Agent 安全漏洞 CWE-250 7.8 -2023-03-29
CVE-2022-3872 QEMU 安全漏洞 CWE-193 6.5 -2022-11-07
CVE-2022-3165 QEMU 数字错误漏洞 CWE-191 6.5 -2022-10-17
CVE-2022-2962 QEMU 缓冲区错误漏洞 CWE-400 8.8 -2022-09-13
CVE-2021-3735 QEMU 安全漏洞 CWE-667 4.4 -2022-08-26
CVE-2022-0216 QEMU 资源管理错误漏洞 CWE-416 6.0 -2022-08-26
CVE-2021-3929 QEMU 资源管理错误漏洞 CWE-416 8.2 -2022-08-25
CVE-2021-4158 QEMU 代码问题漏洞 CWE-476 6.5 -2022-08-24
CVE-2020-14394 QEMU 安全漏洞 CWE-835 6.0 -2022-08-17
CVE-2021-3611 QEMU 缓冲区错误漏洞 CWE-119 6.5 -2022-05-11
CVE-2021-3750 QEMU 资源管理错误漏洞 CWE-416 8.2 -2022-05-02
CVE-2021-4206 QEMU 安全漏洞 CWE-190 8.2 -2022-04-29
CVE-2021-4207 QEMU 安全漏洞 CWE-362 8.2 -2022-04-29
CVE-2021-20295 Red Hat Enterprise Linux 缓冲区错误漏洞 CWE-125 7.1 -2022-04-01
CVE-2022-1050 Guest 资源管理错误漏洞 CWE-416 8.8 -2022-03-29
CVE-2021-3582 QEMU 缓冲区错误漏洞 CWE-119 6.5 -2022-03-25
CVE-2021-20257 QEMU 安全漏洞 CWE-835 6.5 -2022-03-16
CVE-2021-3638 QEMU 缓冲区错误漏洞 CWE-787 6.5 -2022-03-03
CVE-2021-3608 QEMU 缓冲区错误漏洞 CWE-824 6.0 -2022-02-24
CVE-2021-3607 QEMU 输入验证错误漏洞 CWE-190 6.0 -2022-02-24
CVE-2021-3947 QEMU 缓冲区错误漏洞 CWE-125 5.5 -2022-02-18
CVE-2021-3930 QEMU 安全漏洞 CWE-193 6.5 -2022-02-18
CVE-2021-4145 QEMU 代码问题漏洞 CWE-476 3.8 -2022-01-25

All 77 known CVE vulnerabilities affecting QEMU with full Chinese analysis, references, and POCs where available.