CVE-2026-2243
Wolfi vulnerability analysis and mitigation

Overview

CVE-2026-2243 is a heap buffer out-of-bounds read vulnerability in QEMU's VMDK compressed grain parsing code (block/vmdk.c). A specially crafted VMDK image can cause qemu-img or QEMU with a VMDK disk to read past an allocated buffer, potentially resulting in a 12-byte information leak or a denial of service (DoS) condition. The vulnerability was reported on February 19, 2026, and affects QEMU (qemu-kvm). It carries a CVSS v3.1 base score of 5.1 (Medium) (Feedly, Red Hat Bugzilla).

Technical details

The root cause is an out-of-bounds read (CWE-125) in block/vmdk.c, where QEMU's VMDK driver fails to properly validate buffer boundaries when parsing compressed grain data in a VMDK image. An attacker can craft a malicious VMDK file that causes the parser to read up to 12 bytes beyond the end of an allocated heap buffer. The attack vector is local (AV:L), requires no privileges (PR:N), and no user interaction (UI:N). The upstream fix was committed to the QEMU project repository (Red Hat Bugzilla, QEMU Upstream Fix).

Impact

Successful exploitation can lead to a limited confidentiality impact through a 12-byte heap memory leak, which could potentially expose sensitive in-memory data, and a low availability impact through a denial of service condition. Integrity is not affected. The scope is limited to the QEMU process itself; however, in virtualized environments, information leakage from the hypervisor process could have implications for guest isolation (Red Hat Bugzilla, Feedly).

Exploitability

No public exploit code or in-the-wild exploitation has been reported for CVE-2026-2243. The EPSS score is approximately 0.013% (0.000130), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The vulnerability was credited to researcher Halil Oktay (oblivionsage) (Red Hat Bugzilla, Feedly).

Exploitation steps

  1. Craft a malicious VMDK image: Create a specially crafted VMDK file with a malformed compressed grain header or data structure that causes the parser in block/vmdk.c to miscalculate buffer boundaries.
  2. Deliver the VMDK image: Place the crafted VMDK file in a location accessible to the target QEMU instance — for example, as a virtual disk image for a VM, or as input to qemu-img.
  3. Trigger parsing: Start a QEMU virtual machine using the malicious VMDK as a disk image, or run qemu-img info / qemu-img convert against the crafted file to trigger the vulnerable code path.
  4. Observe the result: The out-of-bounds read occurs during compressed grain parsing, potentially leaking up to 12 bytes of heap memory content or causing a crash (DoS) of the QEMU process (Red Hat Bugzilla).

Indicators of compromise

  • File System: Presence of unexpected or externally supplied VMDK files with unusual compressed grain structures in VM storage directories.
  • Logs: QEMU process crash logs or segmentation fault entries in system logs (/var/log/syslog, journalctl) associated with VMDK image parsing.
  • Process: Abnormal termination (SIGABRT, SIGSEGV) of qemu-kvm or qemu-img processes when processing VMDK disk images.

Mitigation and workarounds

The upstream fix has been committed to the QEMU project repository (QEMU Upstream Fix). Downstream distributions including Amazon Linux 2 (ALAS2-2026-3182), Ubuntu (USN-8161-1, USN-8412-1), SUSE (SUSE-SU-202621883-1), and openSUSE have released patched packages — administrators should apply the relevant distribution update as soon as possible. As a workaround where patching is not immediately feasible, avoid processing untrusted or externally supplied VMDK images with qemu-img or QEMU (Amazon Linux Advisory, Ubuntu Advisory, SUSE Advisory).

Community reactions

The vulnerability received standard coverage from Linux distribution security teams, with advisories issued by Amazon Linux, Ubuntu, SUSE, and openSUSE. A technical write-up was published by Infinit Security detailing the heap buffer out-of-bounds read in VMDK compressed grain parsing (Infinit Security). No significant social media controversy or high-profile researcher commentary beyond standard disclosure was observed.

Additional resources


SourceThis report was generated using AI

Related Wolfi vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-45808HIGH7.1
  • Wolfi logoWolfi
  • openbao
NoYesAug 07, 2026
CVE-2026-6791MEDIUM6.6
  • Wolfi logoWolfi
  • glibc
NoYesAug 10, 2026
CVE-2026-46358MEDIUM5.4
  • Wolfi logoWolfi
  • openbao-debuginfo
NoYesAug 07, 2026
CVE-2026-46405MEDIUM5.3
  • Wolfi logoWolfi
  • openbao
NoYesAug 07, 2026
CVE-2026-69207MEDIUM5.3
  • JavaScript logoJavaScript
  • gemini-cli
NoYesAug 07, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management