1sealsemantic last-mile verification

Research / Finding

Qemu-kvm: hyperv/syndbg: missing mapped-length guard after cpu_physical_memory_map causes host oob write

F-QEMU-001-001

Public snapshot: 26 Sep 2026. Status, releases and attribution belong to each source below; none is inferred from another record.

Read the evidence · View in research browse

Recorded evidence

—score not recorded
CVE-2026-3842CVEqemu/qemu

Qemu-kvm: hyperv/syndbg: missing mapped-length guard after cpu_physical_memory_map causes host oob write

Fixed in: upstream commit 4f28b87fdd24

patched
details
Finding IDs
F-QEMU-001-001
CVE
CVE-2026-3842
Status
patched
Fixed in
upstream commit 4f28b87fdd24
Recorded credit
Reported-by: Oleh Konko <https://github.com/1seal>
Note
public Red Hat CVE record; upstream QEMU commit 4f28b87fdd24df2049626106b7c24d0180952115 from 2026-03-09 carries Fixes: CVE-2026-3842 and Reported-by: Oleh Konko; public backport/cherry-pick 85af4e93 followed on 2026-03-13.
CVE registry state
PUBLISHED
CVE state checked

F-QEMU-001-001: Memory safety. Mapped physical-memory length is not checked before the affected access. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.

Mechanism source for F-QEMU-001-001

Security area (1seal assessment): Memory safety. Mapped physical-memory length is not checked before the affected access. Reviewed 24 Sep 2026.

—score not recorded
qemu/qemuReported fixqemu/qemu

hyperv/syndbg: check length returned by cpu_physical_memory_map()

merged
details
Finding IDs
F-QEMU-001-001
Status
merged
Reported via
private security contact
Note
public upstream commit 4f28b87fdd24 on 2026-03-09 adds the returned-length check before writing mapped guest memory, includes Fixes: CVE-2026-3842 and Reported-by: Oleh Konko, with public backport/cherry-pick 85af4e93 on 2026-03-13.

F-QEMU-001-001: Memory safety. Mapped physical-memory length is not checked before the affected access. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.

Mechanism source for F-QEMU-001-001

Security area (1seal assessment): Memory safety. Mapped physical-memory length is not checked before the affected access. Reviewed 24 Sep 2026.

Clarify or correct this record privately. The email subject includes the finding ID. For an existing case, continue the agreed private thread. Do not post unpublished vulnerability details in public issues. Research disclosure policy.

How this page groups evidence

This identifier groups recorded evidence; it is not an additional CVE, independent-vulnerability count or guarantee of vendor confirmation. Fixed code, released versions, attribution and independent discovery are distinct claims. Absent metadata means not recorded, not disproved. Counting rules.