VDB
CVE-2026-0665
CVE-2026-0665
PUBLISHED
CVSS 6.5 MEDIUM
An off-by-one error was found in QEMU's KVM Xen guest support. A malicious guest could use this flaw to trigger out-of-bounds heap accesses in the QEMU process via the emulated Xen physdev hypercall interface, leading to a denial of service or potential memory corruption.
EPSS 0.01% · 0.8th percentile
Risk Scores
CVSS v3.1
6.5
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
EPSS Score
0.01%
0.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat OpenShift Container Platform 4 | |
| Red Hat | Red Hat Enterprise Linux 9 | |
| Red Hat | Red Hat Enterprise Linux 8 | |
| Red Hat | Red Hat Enterprise Linux 6 | |
| 8.0.0, 8.0.0 | ||
| Red Hat | Red Hat Enterprise Linux 7 | |
| Red Hat | Red Hat Enterprise Linux 7 | |
| Red Hat | Red Hat Enterprise Linux 10 |
Timeline
- Feb 6, 2026 PoC Published
- Feb 18, 2026 CVE Published
- Feb 18, 2026 CVE Updated
- Feb 19, 2026 EPSS Score
- Feb 20, 2026 EPSS Score
- Feb 21, 2026 EPSS Score
- Feb 23, 2026 EPSS Score
- Feb 24, 2026 EPSS Score
- Feb 25, 2026 EPSS Score
- Feb 26, 2026 EPSS Score
- Feb 27, 2026 EPSS Score
- Feb 28, 2026 EPSS Score