CVE-2026-5164Disclosure(redhat / enterprise_linux)

LOWCVSS 5.5 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw was found in virtio-win. The `RhelDoUnMap()` function does not properly validate the number of descriptors provided by a user during an unmap request. A local user could exploit this input validation vulnerability by supplying an excessive number of descriptors, leading to a buffer overrun. This can cause a system crash, resulting in a Denial of Service (DoS).

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-120

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • enterprise_linux
  • virtio-win

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-03-31)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
enterprise_linuxvirtio-win

3 versions affected across 2 products

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-30: 1Mentions · 2026-03-31: 2Technical Details · 2026-03-30: 1Technical Details · 2026-03-31: 203-3003-31
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-301
General1
2026-03-312
Disclosure2
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-5164 A flaw was found in virtio-win. The `RhelDoUnMap()` function does not properly validate the number of descriptors provided by a user during an unmap request. A local us… https://www.cve.org/CVERecord?id=CVE-2026-5164 ----- Traducción: Se encontró una f… http://infoflow.cloud`

    Post summary

    CVE-2026-5164 is a newly disclosed flaw in virtio-win where the RhelDoUnMap() function does not validate descriptor counts. No PoC, exploit, active usage, patch, or debunking information is provided.

    0000026
    65 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5164 A flaw was found in virtio-win. The `RhelDoUnMap()` function does not properly validate the number of descriptors provided by a user during an unmap request. A local us… https://www.cve.org/CVERecord?id=CVE-2026-5164

    Post summary

    The excerpt reports a local privilege issue in virtio‑win due to improper descriptor validation in the `RhelDoUnMap()` function, but provides no exploit, PoC, patch, or active exploitation data.

    00000229
    56.9K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-5164 - Virtio-win: virtio-win: denial of service via unvalidated descriptor count in unmap request Intel Report: https://ift.tt/yaBcFnI

    Post summary

    The post announces CVE-2026-5164 as a denial-of-service vulnerability in Virtio-win, but offers no PoC, exploit code, patch info, or evidence of active exploitation.

    0000045
    280 followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
OSredhatenterprise_linux10.0--
OSredhatenterprise_linux9.0--
Appredhatvirtio-win---

Explore more