CVE-2026-5165 Details
Description
A flaw was found in virtio-win, specifically within the VirtIO Block (BLK) device. When the device undergoes a reset, it fails to properly manage memory, resulting in a use-after-free vulnerability. This issue could allow a local attacker to corrupt system memory, potentially leading to system instability or unexpected behavior.
A use-after-free vulnerability has been identified in the VirtIO Block (BLK) device of virtio-win. This flaw occurs when the device is reset, as it improperly handles memory management. A local attacker could exploit this vulnerability to corrupt system memory, potentially causing system instability or unexpected behavior.
A fix for this vulnerability has been implemented and is available in the latest version of the virtio-win KVM guest drivers for Windows.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-5165 | [email protected] | Vendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2453015 | [email protected] | Issue TrackingVendor Advisory |
| https://github.com/virtio-win/kvm-guest-drivers-windows/pull/1493 | [email protected] | Issue Tracking |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-825 | Expired Pointer Dereference | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| redhat virtio-win | All versions |
CPE
Remediation
| |
| redhat enterprise linux | 9.0 10.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 28, 2026 | Initial Analysis | [email protected] |
| Mar 30, 2026 | New CVE Received | [email protected] |