CVE-2026-3196 Details
Description
An integer overflow vulnerability was found in the virtio-snd device via PCM_INFO requests from the guest. A malicious guest can provide out-of-bounds stream counts, potentially leading to unbounded memory allocation on the host and a denial of service condition.
An integer overflow vulnerability has been identified in the QEMU virtualization component, specifically within the virtio-snd device. This vulnerability arises from PCM_INFO requests originating from a guest. A malicious guest can exploit this by sending out-of-bounds stream counts, which may result in unbounded memory allocation on the host. Consequently, this could create a denial-of-service condition by exhausting available memory resources.
The QEMU packages included with Red Hat Enterprise Linux are not affected by this vulnerability, as the virtio-snd device is disabled at build-time. However, for users of QEMU in other environments, the upstream patch for this vulnerability is available in the QEMU GitLab repository.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-3196 | [email protected] | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2443789 | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-190 | Integer Overflow or Wraparound | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 22, 2026 | CVE Modified | CISA-ADP |
| Jun 19, 2026 | New CVE Received | [email protected] |