Still unfixed in qemu 1:10.2.1+ds-1ubuntu3.2 (resolute). The changelog for 1:10.2.1+ds-1ubuntu3.2 contains no reference to CVE-2026-3886, and no patch touching calc_image_hostmem() in hw/display/virtio-gpu.c.
Upstream status is unchanged: fixed by commit 2a28de12bae5, released in QEMU v10.2.3 on 2026-05-26. ** CVE added: https://cve.org/CVERecord?id=CVE-2026-3886 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2162697 Title: CVE-2026-3886: virtio-gpu integer overflow (calc_image_hostmem) unfixed in qemu 1:10.2.1+ds-1ubuntu3.1 To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/qemu/+bug/2162697/+subscriptions -- ubuntu-bugs mailing list [email protected] https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
