CVE-2025-54566
Wolfi vulnerability analysis and mitigation

Overview

A migration state inconsistency vulnerability was discovered in QEMU through version 10.0.3, specifically within the hw/pci/pcie_sriov.c component. The vulnerability was assigned CVE-2025-54566 and was publicly disclosed on July 24, 2025. This security flaw is related to CVE-2024-26327 and affects the PCI-E SR-IOV emulation code (NVD, Debian Tracker).

Technical details

The vulnerability has been assigned a CVSS v3.1 base score of 4.2 (Medium) with the vector string CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L. The flaw is categorized under CWE-642 (External Control of Critical State Data). The issue was introduced in QEMU version 10.0.0-rc0 through two specific commits (Red Hat CVE, Debian Tracker).

Impact

The vulnerability can result in unexpected behavior and potential resource exhaustion, leading to denial of service conditions. The impact is particularly relevant during migration processes where state mismatches can occur (Red Hat CVE).

Mitigation and workarounds

According to Red Hat, mitigation options are either not available or do not meet their Product Security criteria for ease of use, deployment, and stability. Several versions of Red Hat Enterprise Linux (6, 7, 8, and 9) are not affected by this vulnerability, while RHEL 10 has a fix deferred status (Red Hat CVE).

Additional resources


SourceThis report was generated using AI

Related Wolfi vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-67818HIGH7.2
  • WolfiWolfi
  • weaviate-1.30
NoYesDec 12, 2025
CVE-2025-67499MEDIUM6.6
  • PodmanPodman
  • containerd-fips
NoYesDec 10, 2025
CVE-2025-67721MEDIUM6.3
  • JavaJava
  • io.airlift:aircompressor-v3
NoYesDec 12, 2025
CVE-2025-64702MEDIUM5.3
  • SyncthingSyncthing
  • github.com/quic-go/quic-go
NoYesDec 11, 2025
CVE-2025-67819MEDIUM4.9
  • WolfiWolfi
  • weaviate-1.31
NoYesDec 12, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management