
Cloud Vulnerability DB
A community-led vulnerabilities database
The vulnerability identified as CVE-2025-54567 affects QEMU through version 10.0.3, specifically in the hw/pci/pcie_sriov.c component. The issue was disclosed on July 24, 2025, and involves mishandling of the VF Enable bit write mask, which is related to CVE-2024-26327 (NVD).
The vulnerability has been assigned a CVSS v3.1 Base Score of 4.2 (MEDIUM) with the vector string CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L. The issue has been classified under CWE-684 (Incorrect Provision of Specified Functionality). The technical nature of the vulnerability involves mishandling of the VF Enable bit write mask in the SR-IOV implementation (MITRE).
Based on the CVSS scoring, the vulnerability has low impact on both integrity and availability, with no direct impact on confidentiality. The attack requires adjacent network access and has high attack complexity (Red Hat).
According to Red Hat's assessment, mitigation options are either not available or do not meet their Product Security criteria for ease of use, deployment, applicability to widespread installation base, or stability (Red Hat).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."