QEMU fixes OOB read in USB CCID smartcard reader
CVE-2026-18204 closes a guest-triggerable out-of-bounds read in the emulated bulk-in response ring.
Marc-André Lureau has fixed an out-of-bounds read in QEMU's emulated USB CCID smartcard reader, tracked as CVE-2026-18204.
The device keeps a small ring of pending bulk-in responses. A guest could fill that ring, partially read one response (leaving a non-zero offset), then send another command whose reply reused the still-active slot. The stale offset could exceed the new payload length, so an unsigned length calculation wrapped and the copy path read past the end of the buffer.
The fix keeps each ring slot marked busy until it is fully released, rather than dropping the pending count when the slot first becomes active, and adds a guard before the subtraction. Lureau notes that a conforming host is unlikely to hit the bug in practice: the device advertises a single busy slot, so only one command should be in flight at a time.
The issue was reported by Warisjeet Singh.