Reported-by: Oleh Konko <https://github.com/1seal>
Note
public Red Hat CVE record; upstream QEMU commit 4f28b87fdd24df2049626106b7c24d0180952115 from 2026-03-09 carries Fixes: CVE-2026-3842 and Reported-by: Oleh Konko; public backport/cherry-pick 85af4e93 followed on 2026-03-13.
CVE registry state
PUBLISHED
CVE state checked
F-QEMU-001-001: Memory safety. Mapped physical-memory length is not checked before the affected access. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
hyperv/syndbg: check length returned by cpu_physical_memory_map()
merged
details
Finding IDs
F-QEMU-001-001
Status
merged
Reported via
private security contact
Note
public upstream commit 4f28b87fdd24 on 2026-03-09 adds the returned-length check before writing mapped guest memory, includes Fixes: CVE-2026-3842 and Reported-by: Oleh Konko, with public backport/cherry-pick 85af4e93 on 2026-03-13.
F-QEMU-001-001: Memory safety. Mapped physical-memory length is not checked before the affected access. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
This identifier groups recorded evidence; it is not an additional CVE, independent-vulnerability count or guarantee of vendor confirmation. Fixed code, released versions, attribution and independent discovery are distinct claims. Absent metadata means not recorded, not disproved. Counting rules.