
Two more QEMU CVEs dropped 🔥 CVE-2026-17516 → VGA panning_buf heap OOB WRITEafter text/graphics mode switch (Default) CVE-2026-18204 → USB smartcard-reader OOB read in bulk-in ring Both guest-triggerable. Patches already up. https://patchew.org/QEMU/20260728151456.3704099-1-marcandre.lureau@redhat.com/ https://patchew.org/QEMU/20260729075743.333920-1-marcandre.lureau@redhat.com/
Post summary
Two new QEMU vulnerabilities (CVE-2026-17516 and CVE-2026-18204) have been disclosed, detailing out‑of‑bounds heap write and read conditions, with patches already released and linked.
