Impacted Products
- CubeCOS
Introduction
This advisory covers CVE-2026-3195.
The vulnerable code is not present in CubeCOS, nor is it used by CubeOS.
A flaw was found in QEMU-KVM. When reading input audio in the virtio-snd device input callback, the virtio_snd_pcm_in_cb function did not check whether the iov could fit the data buffer, potentially leading to a heap out-of-bounds write. This issue exists due to an incomplete fix for CVE-2024-7730.
Risk Assessment & Exposure
Analysis of the CubeCOS runtime environment and software configuration confirms that the vulnerable Virtio-SND package is neither included nor used by CubeOS.
Customer Actions Required
None.
References
List
Change Log
| Date | Description |
|---|---|
| 2026-06-22 | Issue intake |
| 2026-06-22 | Issue triage and impact evaluation |
| 2026-06-22 | First publication |
