
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-2243 is a heap buffer out-of-bounds read vulnerability in QEMU's VMDK compressed grain parsing code (block/vmdk.c). A specially crafted VMDK image can cause qemu-img or QEMU with a VMDK disk to read past an allocated buffer, potentially resulting in a 12-byte information leak or a denial of service (DoS) condition. The vulnerability was reported on February 19, 2026, and affects QEMU (qemu-kvm). It carries a CVSS v3.1 base score of 5.1 (Medium) (Feedly, Red Hat Bugzilla).
The root cause is an out-of-bounds read (CWE-125) in block/vmdk.c, where QEMU's VMDK driver fails to properly validate buffer boundaries when parsing compressed grain data in a VMDK image. An attacker can craft a malicious VMDK file that causes the parser to read up to 12 bytes beyond the end of an allocated heap buffer. The attack vector is local (AV:L), requires no privileges (PR:N), and no user interaction (UI:N). The upstream fix was committed to the QEMU project repository (Red Hat Bugzilla, QEMU Upstream Fix).
Successful exploitation can lead to a limited confidentiality impact through a 12-byte heap memory leak, which could potentially expose sensitive in-memory data, and a low availability impact through a denial of service condition. Integrity is not affected. The scope is limited to the QEMU process itself; however, in virtualized environments, information leakage from the hypervisor process could have implications for guest isolation (Red Hat Bugzilla, Feedly).
No public exploit code or in-the-wild exploitation has been reported for CVE-2026-2243. The EPSS score is approximately 0.013% (0.000130), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The vulnerability was credited to researcher Halil Oktay (oblivionsage) (Red Hat Bugzilla, Feedly).
block/vmdk.c to miscalculate buffer boundaries.qemu-img.qemu-img info / qemu-img convert against the crafted file to trigger the vulnerable code path./var/log/syslog, journalctl) associated with VMDK image parsing.qemu-kvm or qemu-img processes when processing VMDK disk images.The upstream fix has been committed to the QEMU project repository (QEMU Upstream Fix). Downstream distributions including Amazon Linux 2 (ALAS2-2026-3182), Ubuntu (USN-8161-1, USN-8412-1), SUSE (SUSE-SU-202621883-1), and openSUSE have released patched packages — administrators should apply the relevant distribution update as soon as possible. As a workaround where patching is not immediately feasible, avoid processing untrusted or externally supplied VMDK images with qemu-img or QEMU (Amazon Linux Advisory, Ubuntu Advisory, SUSE Advisory).
The vulnerability received standard coverage from Linux distribution security teams, with advisories issued by Amazon Linux, Ubuntu, SUSE, and openSUSE. A technical write-up was published by Infinit Security detailing the heap buffer out-of-bounds read in VMDK compressed grain parsing (Infinit Security). No significant social media controversy or high-profile researcher commentary beyond standard disclosure was observed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."