PT-2025-35349 · Qemu+1 · Qemu+1
Published
2025-01-01
·
Updated
2026-02-18
·
CVE-2025-8860
CVSS v3.1
3.3
Low
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
qemu (affected versions not specified)
Description
The vulnerability involves an information disclosure issue in QEMU. A heap buffer is allocated without being zeroed, potentially exposing residual data from prior allocations. This data can be read back to the guest when accessing register UEFI VARS REG PIO BUFFER TRANSFER via the
uefi vars read callback function, leading to the disclosure of sensitive process memory or metadata. The issue occurs when a guest writes to register UEFI VARS REG BUFFER SIZE, triggering the uefi vars write callback.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Qemu