CVE-2026-5164

A flaw was found in virtio-win. The `RhelDoUnMap()` function does not properly validate the number of descriptors provided by a user during an unmap request. A local user could exploit this input validation vulnerability by supplying an excessive number of descriptors, leading to a buffer overrun. This can cause a system crash, resulting in a Denial of Service (DoS).
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:redhat:virtio-win:-:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*

History

28 Apr 2026, 14:22

Type Values Removed Values Added
CPE cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:virtio-win:-:*:*:*:*:*:*:*
References () https://access.redhat.com/security/cve/CVE-2026-5164 - () https://access.redhat.com/security/cve/CVE-2026-5164 - Vendor Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2453014 - () https://bugzilla.redhat.com/show_bug.cgi?id=2453014 - Issue Tracking, Vendor Advisory
References () https://github.com/virtio-win/kvm-guest-drivers-windows/pull/1504 - () https://github.com/virtio-win/kvm-guest-drivers-windows/pull/1504 - Issue Tracking, Patch
First Time Redhat
Redhat virtio-win
Redhat enterprise Linux

01 Apr 2026, 14:24

Type Values Removed Values Added
Summary
  • (es) Se encontró una falla en virtio-win. La función 'RhelDoUnMap()' no valida correctamente el número de descriptores proporcionados por un usuario durante una solicitud de desmapeo. Un usuario local podría explotar esta vulnerabilidad de validación de entrada al proporcionar un número excesivo de descriptores, lo que lleva a un desbordamiento de búfer. Esto puede causar una caída del sistema, resultando en una denegación de servicio (DoS).

30 Mar 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-30 15:16

Updated : 2026-04-28 14:22


NVD link : CVE-2026-5164

Mitre link : CVE-2026-5164

CVE.ORG link : CVE-2026-5164


JSON object : View

Products Affected

redhat

  • enterprise_linux
  • virtio-win
CWE
CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')