Still unfixed in qemu 1:10.2.1+ds-1ubuntu3.2 (resolute).

The changelog for 1:10.2.1+ds-1ubuntu3.2 contains no reference to
CVE-2026-3886, and no patch touching calc_image_hostmem() in
hw/display/virtio-gpu.c.

Upstream status is unchanged: fixed by commit 2a28de12bae5, released in
QEMU v10.2.3 on 2026-05-26.

** CVE added: https://cve.org/CVERecord?id=CVE-2026-3886

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2162697

Title:
  CVE-2026-3886: virtio-gpu integer overflow (calc_image_hostmem)
  unfixed in qemu 1:10.2.1+ds-1ubuntu3.1

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/qemu/+bug/2162697/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to