
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-65929 is an out-of-bounds access vulnerability in QEMU's DMG (Apple Disk Image) component that can potentially lead to a crash. The CVE was reserved and first detected by Feedly on July 23, 2026, with subsequent coverage by Nessus (plugin 341590) and Qualys (detection 6600572). The affected product is QEMU, though specific version ranges have not been publicly disclosed at this time. The estimated CVSS severity is Medium (Feedly).
The vulnerability is rooted in an out-of-bounds memory access (CWE-125) within QEMU's DMG component, which handles Apple Disk Image file parsing. An out-of-bounds read or write in this component can be triggered when processing a maliciously crafted DMG image, potentially causing the QEMU process to crash. A related commit has been identified in the QEMU repository (commit 86acc650be113d7007bbb1499a4f50bda5c6d705) that appears to address this issue (QEMU Commit). Full technical details and a formal advisory have not yet been published as the CVE remains in reserved status.
Successful exploitation of this vulnerability can cause a denial of service (DoS) by crashing the QEMU process. Since QEMU is commonly used as a hypervisor or emulator in virtualized environments, a crash could disrupt guest virtual machines and affect availability of hosted workloads. There is no current evidence suggesting confidentiality or integrity impacts beyond the crash, though out-of-bounds access vulnerabilities can sometimes be further developed into more severe exploits (Feedly).
There are no known public proof-of-concept exploits or reports of in-the-wild exploitation for CVE-2026-65929 at this time (Feedly). The CVE is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, and no threat actor attribution has been reported. The EPSS score has not been publicly disclosed. Detection signatures have been added by Nessus (plugin 341590) and Qualys (detection 6600572), indicating vendor-level awareness (Tenable).
Users should apply the fix introduced in QEMU commit 86acc650be113d7007bbb1499a4f50bda5c6d705 or upgrade to a patched QEMU release once officially announced (QEMU Commit). Debian has issued a security update addressing this issue as of September 12, 2026 (Debian Advisory). As a workaround, administrators can restrict or disable the use of DMG disk image files within QEMU environments where this functionality is not required. Monitor official QEMU and distribution-specific advisories for further patch guidance.
Debian issued a security announcement on September 12, 2026, acknowledging the vulnerability and providing updated packages (Debian Advisory). Tenable added Nessus detection plugins (341590 and 343529) to identify vulnerable systems (Tenable). No notable researcher commentary or broader media coverage has been identified beyond vendor-level detection and patching activity.
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."