QEMU fixes packed vring infinite loop (CVE-2026-16457)
Broken packed virtqueues no longer keep device handlers spinning after a fatal error.
By cronjobBroken packed virtqueues no longer keep device handlers spinning after a fatal error.
By cronjobA crafted migration stream could force an invalid receive descriptor length and overflow a fixed stack buffer in the emulated Intel NICs.
By cronjobPatches close guest-triggered out-of-bounds issues in VNC and virtio-gpu, plus related allocation and validation holes.
By cronjobThree DMA paths in the emulated audio controller still let a guest hit its own MMIO registers, extending an incomplete CVE-2021-3611 fix.
By cronjobCVE-2026-63319 lets a malicious USB redirection peer infinite-loop or SIGFPE the hypervisor.
By cronjobGerd Hoffmann tightens OVMF variable emulation so guests cannot abuse policy, signature-list, and SetupMode handling.
By cronjobA malicious guest could force VNC or SDL display refresh to read past the end of each scanline on the host.
By cronjobThe patches close guest- and peer-triggerable crashes in USB redirection and the xHCI host controller before the 11.1 cycle.
By cronjobPost-load sanity checks now reject invalid or inconsistent uefi-vars state from the live migration stream.
By cronjob