
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-3886 is an integer overflow vulnerability in the QEMU virtio-gpu driver that allows local attackers to escalate privileges from a guest system to the host. An attacker must first obtain the ability to execute low-privileged code on the target guest system to exploit this flaw. The vulnerability was first tracked in March 2026 and publicly disclosed via a Zero Day Initiative advisory on June 9, 2026. It carries a CVSS v3.0 base score of 8.8 (High) (ZDI Advisory).
The root cause is improper validation of user-supplied data within the QEMU virtio-gpu driver, leading to an integer overflow condition before a buffer is allocated (CWE-190: Integer Overflow or Wraparound). By supplying crafted input through the virtio-gpu interface from within a guest VM, an attacker can trigger the overflow and potentially execute arbitrary code in the context of the host system. A patch was issued by the QEMU project and details are available at the upstream patchwork submission (ZDI Advisory, QEMU Patch).
Successful exploitation enables a guest-to-host escape, allowing an attacker with low-privileged code execution inside a VM to escalate privileges and execute arbitrary code on the underlying host system. This represents a full hypervisor breakout scenario with high impact to confidentiality, integrity, and availability of the host and potentially all other VMs running on the same hypervisor. The changed scope (S:C) in the CVSS vector reflects the cross-boundary nature of this impact (ZDI Advisory).
/var/log/syslog, journalctl)./tmp or QEMU runtime directories.QEMU has released a patch addressing this vulnerability; administrators should update QEMU to the latest patched version as soon as possible (ZDI Advisory, QEMU Patch). Debian has issued security updates addressing this CVE as part of its release cycle (Debian Advisory), and SUSE has published corresponding advisories (SUSE-SU-2026:22550-1, SUSE-SU-2026:22576-1). As a workaround where patching is not immediately possible, consider disabling the virtio-gpu device for guest VMs and using an alternative display backend, or restricting guest VM access to untrusted users.
The vulnerability received coverage from security news outlets and the broader infosec community following the ZDI advisory publication in June 2026. A threat intelligence report highlighted the guest-to-host escape nature of the flaw (DeafNews). VulDB tracked the vulnerability and it was discussed on Infosec.exchange, reflecting moderate community interest given the severity of the hypervisor escape scenario. Loginsoft also referenced the vulnerability in a broader analysis of active exploitation trends (Loginsoft Medium).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."