Security Advisory

CVE-2026-3195 virtio-snd: heap buffer overflow in virtio_snd_pcm_in_cb

  • Advisory ID: CVE-2026-3195
  • Severity: Low
  • CVE(s): CVE-2026-3195
  • Affected Products: CubeCOS
  • Updated On: 2026-06-22

Impacted Products

  • CubeCOS

Introduction

This advisory covers CVE-2026-3195.

The vulnerable code is not present in CubeCOS, nor is it used by CubeOS.

A flaw was found in QEMU-KVM. When reading input audio in the virtio-snd device input callback, the virtio_snd_pcm_in_cb function did not check whether the iov could fit the data buffer, potentially leading to a heap out-of-bounds write. This issue exists due to an incomplete fix for CVE-2024-7730.

Risk Assessment & Exposure

Analysis of the CubeCOS runtime environment and software configuration confirms that the vulnerable Virtio-SND package is neither included nor used by CubeOS.

Customer Actions Required

None.

References

List

Change Log

Date Description
2026-06-22 Issue intake
2026-06-22 Issue triage and impact evaluation
2026-06-22 First publication

Contact Us