CVE-2026-0665General

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

An off-by-one error was found in QEMU's KVM Xen guest support. A malicious guest could use this flaw to trigger out-of-bounds heap accesses in the QEMU process via the emulated Xen physdev hypercall interface, leading to a denial of service or potential memory corruption.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-02-06); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-02-06: 1Mentions · 2026-02-18: 1Mentions · 2026-03-17: 1Technical Details · 2026-02-18: 1Technical Details · 2026-03-17: 102-0602-1803-17
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-02-061
General1
2026-02-181
Disclosure1
2026-03-171
General1
Full discourse3 posts
  • VulDB 🛡@vuldb
    General

    The severity is increased for this new vulnerability affecting QEMU (CVE-2026-0665) https://vuldb.com/?id.344679

    Post summary

    The text briefly notes a severity increase for CVE-2026-0665 affecting QEMU, but provides no details on exploitation, patching, or technical specifics.

    0100067
    2.1K followersView on X
  • itewqq@lyq_sqsp
    General

    I think it depends on the setup. We reported a heap off-by-one in KVM’s Xen support earlier this year, so the code base is not that perfect I think. However, the bug (CVE-2026-0665) was just a MEDIUM (i think it’s fair) because it need to be attacked from a Xen guest, which is not considered in kvmctf 😂

    Post summary

    The post discusses CVE-2026-0665 as a heap off-by-one in KVM’s Xen support, noting it earned a medium severity due to requiring a Xen guest, with no PoC, exploit code, patch, or active exploitation mentioned.

    00000504
    2.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-0665 An off-by-one error was found in QEMU's KVM Xen guest support. A malicious guest could use this flaw to trigger out-of-bounds heap accesses in the QEMU process via the … https://www.cve.org/CVERecord?id=CVE-2026-0665

    Post summary

    An off-by-one error in QEMU's KVM Xen guest support can lead to out-of-bounds heap accesses in the QEMU process, with no PoC, exploit, or patch information provided.

    00000118
    56.4K followersView on X

Explore more