
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-66022 is a DMA re-entrancy vulnerability in QEMU's virtio-net implementation. The flaw allows DMA re-entrancy protection to be bypassed because the bus and device were not using the same guarded bottom-half function, enabling unsafe DMA re-entrancy behavior. The CVE is currently in "Reserved" status, and the estimated CVSS severity is Medium. The vulnerability affects the QEMU hypervisor and was first tracked by Feedly on July 24, 2026 (Feedly).
The root cause is a synchronization flaw (related to CWE-362, race condition / improper synchronization) in QEMU's virtio-net device emulation. DMA (Direct Memory Access) re-entrancy protection is designed to prevent a guest from triggering nested DMA operations that could corrupt hypervisor state, but the bus and device components were using different guarded bottom-half functions, leaving a window for unsafe re-entrant DMA access. A fix was committed to the QEMU upstream repository (QEMU Commit). No public proof-of-concept exploit code has been identified at this time.
Successful exploitation of this vulnerability could allow a malicious guest operating system or process with access to the virtio-net device to trigger unsafe DMA re-entrancy, potentially leading to memory corruption within the QEMU process on the host. This could result in a denial of service (hypervisor crash) or, in a worst-case scenario, privilege escalation from guest to host, threatening the confidentiality and integrity of other virtual machines sharing the same host (Feedly, QEMU Commit).
There is no evidence of in-the-wild exploitation or public proof-of-concept code for CVE-2026-66022 at this time. The CVE remains in "Reserved" status, and no CISA KEV catalog listing has been identified. The vulnerability has been detected by Nessus (plugin 341593) and Qualys (plugin 6600572), indicating scanner coverage for affected systems (Tenable, Feedly).
The upstream QEMU project has addressed this vulnerability via a patch committed to the QEMU repository (QEMU Commit). Debian has also issued guidance as part of its security advisories (Debian News). Users should update QEMU to a version that includes the fix, and Linux distribution users should apply vendor-provided security updates as they become available. As a workaround, restricting untrusted guest access to virtio-net devices may reduce exposure until patching is possible.
Debian issued a security announcement referencing this CVE in September 2026 (Debian News). Vulnerability scanners from Tenable (Nessus) and Qualys have added detection plugins, indicating the security community is tracking this issue actively (Tenable). No notable researcher commentary or significant social media discussion has been identified beyond standard scanner and advisory coverage.
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."