Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1110 CNY

100%

qemu — Vulnerabilities & Security Advisories 77

All 77 CVE vulnerabilities found in qemu, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known security weaknesses for the QEMU virtualization product under the Common Weakness Enumeration classification. It serves as a centralized reference point for developers, security researchers, and system administrators seeking to understand the historical and current threat landscape associated with this open-source emulator. The content compiled here encompasses a broad spectrum of vulnerability types, including buffer overflows, race conditions, input validation errors, and improper privilege management issues identified in various QEMU releases. The time range covered spans from the early inception of the project through to recent developments, ensuring that both legacy concerns and modern security challenges are documented. This extensive timeline allows for a comprehensive analysis of how the codebase has evolved in response to discovered flaws. Readers can utilize this resource to track vendor advisories issued by the QEMU maintainers and upstream contributors, providing context on how specific issues were addressed. The page facilitates the understanding of specific weakness classes within the context of virtualization software, helping users identify patterns in recurring bugs. Additionally, it offers a detailed look up of the product's vulnerability history, enabling stakeholders to assess risk profiles over time and make informed decisions regarding patch management and security hardening. This structured approach supports better integration of security best practices into deployment pipelines and auditing processes.

Vendor: qemu

CVE IDTitleCVSSSeverityPublished
CVE-2025-54566 QEMU 安全漏洞 CWE-642 4.2 Medium2025-07-25
CVE-2025-54567 QEMU 安全漏洞 CWE-684 4.2 Medium2025-07-25
CVE-2023-2680 Dma reentrancy issue (incomplete fix for cve-2021-3750) CWE-416 7.5 High2023-09-13
CVE-2023-3301 Triggerable assertion due to race condition in hot-unplug CWE-617 5.6 Medium2023-09-13
CVE-2023-3180 Heap buffer overflow in virtio_crypto_sym_op_helper() CWE-122 6.0 Medium2023-08-03
CVE-2023-1386 Qemu: 9pfs: suid/sgid bits not dropped on file write CWE-281 3.3 Low2023-07-24
CVE-2023-3354 Improper i/o watch removal in tls handshake can lead to remote unauthenticated denial of service CWE-476 7.5 High2023-07-11
CVE-2023-0664 QEMU Guest Agent 安全漏洞 CWE-250 7.8 -2023-03-29
CVE-2022-3872 QEMU 安全漏洞 CWE-193 6.5 -2022-11-07
CVE-2022-3165 QEMU 数字错误漏洞 CWE-191 6.5 -2022-10-17
CVE-2022-2962 QEMU 缓冲区错误漏洞 CWE-400 8.8 -2022-09-13
CVE-2021-3735 QEMU 安全漏洞 CWE-667 4.4 -2022-08-26
CVE-2022-0216 QEMU 资源管理错误漏洞 CWE-416 6.0 -2022-08-26
CVE-2021-3929 QEMU 资源管理错误漏洞 CWE-416 8.2 -2022-08-25
CVE-2021-4158 QEMU 代码问题漏洞 CWE-476 6.5 -2022-08-24
CVE-2020-14394 QEMU 安全漏洞 CWE-835 6.0 -2022-08-17
CVE-2021-3611 QEMU 缓冲区错误漏洞 CWE-119 6.5 -2022-05-11
CVE-2021-3750 QEMU 资源管理错误漏洞 CWE-416 8.2 -2022-05-02
CVE-2021-4206 QEMU 安全漏洞 CWE-190 8.2 -2022-04-29
CVE-2021-4207 QEMU 安全漏洞 CWE-362 8.2 -2022-04-29
CVE-2021-20295 Red Hat Enterprise Linux 缓冲区错误漏洞 CWE-125 7.1 -2022-04-01
CVE-2022-1050 Guest 资源管理错误漏洞 CWE-416 8.8 -2022-03-29
CVE-2021-3582 QEMU 缓冲区错误漏洞 CWE-119 6.5 -2022-03-25
CVE-2021-20257 QEMU 安全漏洞 CWE-835 6.5 -2022-03-16
CVE-2021-3638 QEMU 缓冲区错误漏洞 CWE-787 6.5 -2022-03-03
CVE-2021-3608 QEMU 缓冲区错误漏洞 CWE-824 6.0 -2022-02-24
CVE-2021-3607 QEMU 输入验证错误漏洞 CWE-190 6.0 -2022-02-24
CVE-2021-3947 QEMU 缓冲区错误漏洞 CWE-125 5.5 -2022-02-18
CVE-2021-3930 QEMU 安全漏洞 CWE-193 6.5 -2022-02-18
CVE-2021-4145 QEMU 代码问题漏洞 CWE-476 3.8 -2022-01-25

All 77 known CVE vulnerabilities affecting qemu with full Chinese analysis, references, and POCs where available.