CVE-2026-5164 Details
Description
A flaw was found in virtio-win. The `RhelDoUnMap()` function does not properly validate the number of descriptors provided by a user during an unmap request. A local user could exploit this input validation vulnerability by supplying an excessive number of descriptors, leading to a buffer overrun. This can cause a system crash, resulting in a Denial of Service (DoS).
A buffer overrun vulnerability has been identified in virtio-win, specifically within the `RhelDoUnMap()` function. This vulnerability arises because the function fails to properly validate the number of descriptors provided by users during unmap requests. A local user could exploit this flaw by sending an excessive number of descriptors, causing a buffer overrun that leads to a system crash and a denial-of-service condition. This issue affects Windows guests running on Red Hat Enterprise Linux.
Users can upgrade to the latest version of virtio-win, where this vulnerability has been fixed. Red Hat customers can also open a support case to request a prioritization of this issue.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-5164 | [email protected] | Vendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2453014 | [email protected] | Issue TrackingVendor Advisory |
| https://github.com/virtio-win/kvm-guest-drivers-windows/pull/1504 | [email protected] | Issue TrackingPatch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-120 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| redhat virtio-win | All versions |
CPE
Remediation
| |
| redhat enterprise linux | 9.0 10.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 28, 2026 | Initial Analysis | [email protected] |
| Mar 30, 2026 | New CVE Received | [email protected] |