Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-65928
QEMU vulnerability analysis and mitigation

Overview

CVE-2026-65928 is a vulnerability in QEMU's DMG (Apple Disk Image) handling component involving out-of-bounds memory accesses. The CVE is currently in "Reserved" status, meaning full vulnerability details have not yet been publicly disclosed. It is estimated to be of Medium severity based on Feedly AI analysis (Feedly). The vulnerability was first detected in threat discussions around July 2026, with scanner detections appearing in August–September 2026 (Tenable).

Technical details

The vulnerability is rooted in improper bounds checking within QEMU's DMG image parsing code, consistent with CWE-125 (Out-of-bounds Read) or CWE-787 (Out-of-bounds Write). A fix was committed to the QEMU upstream repository (QEMU Commit), indicating the issue was addressed at the source level. Because the CVE remains in Reserved status, the precise attack vector, affected versions, and exploitation preconditions have not been formally published (Feedly).

Impact

Out-of-bounds access vulnerabilities in hypervisor disk image handling components like QEMU's DMG parser can lead to memory corruption, potentially enabling denial of service (crash of the QEMU process) or, in more severe cases, arbitrary code execution within the host context. If exploitable from a guest VM, such vulnerabilities may pose a guest-to-host escape risk, which would have significant confidentiality, integrity, and availability implications for virtualized environments. The full impact scope remains unclear pending official disclosure (Feedly).

Exploitability

No public proof-of-concept exploit code has been identified for CVE-2026-65928, and there is no evidence of in-the-wild exploitation at this time (Feedly). The CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. EPSS score data is not yet available given the Reserved status of the CVE. Detection signatures have been added by Nessus (plugin 341602) and Qualys (detection ID 6600572), suggesting the vulnerability is considered relevant for scanning purposes (Tenable).

Mitigation and workarounds

A fix has been committed to the QEMU upstream repository; users should update to a QEMU version that includes commit 86acc650be113d7007bbb1499a4f50bda5c6d705 or later (QEMU Commit). Debian has issued a security update addressing this issue as of September 2026 (Debian Advisory). As a general workaround, restrict the use of DMG disk image files in QEMU environments where untrusted images may be processed, and monitor vendor channels for official CVE publication and additional guidance (Feedly).

Community reactions

Security scanner vendors Tenable (Nessus) and Qualys have added detection plugins for this vulnerability, indicating awareness within the vulnerability management community (Tenable). Debian has issued a security advisory incorporating the fix, reflecting downstream Linux distribution response (Debian Advisory). No notable public researcher commentary or social media discussion has been identified beyond automated threat intelligence tracking.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

qemu

Affected

sid

qemu: 1:11.1.0+ds-1

Fixed

trixie

qemu: 1:10.0.13+ds-0+deb13u1

Fixed

Ubuntu

Unknown

bionic (esm-infra)

qemu

Unknown

devel

qemu

Unknown

focal (esm-infra)

qemu

Unknown

jammy

qemu

Unknown

noble

qemu

Unknown

resolute

qemu

Unknown

trusty (esm-infra-legacy)

qemu

Unknown

xenial (esm-infra-legacy)

qemu

Unknown

SourceThis report was generated using AI

Related QEMU vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-81627MEDIUM6.7
  • QEMU logoQEMU
  • virt-devel:rhel::qemu-img
NoNoSep 18, 2026
CVE-2026-66022NONEN/A
  • QEMU logoQEMU
  • qemu-img
NoYesAug 31, 2026
CVE-2026-65929NONEN/A
  • QEMU logoQEMU
  • qemu-kvm-common
NoYesAug 31, 2026
CVE-2026-65928NONEN/A
  • QEMU logoQEMU
  • qemu-kvm-block-ssh
NoYesAug 31, 2026
CVE-2026-63323NONEN/A
  • QEMU logoQEMU
  • qemu
NoYesAug 31, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management