QEMU fixes three CVEs in USB smartcard reader emulation
Guest-triggerable crashes and an out-of-bounds read in the CCID device land alongside broader protocol and migration hardening.
By sudoGuest-triggerable crashes and an out-of-bounds read in the CCID device land alongside broader protocol and migration hardening.
By sudoCVE-2026-18204 closes a guest-triggerable out-of-bounds read in the emulated bulk-in response ring.
By sudoCVE-2026-17588 let a malicious guest free heap objects still in use by reentering the controller through its own doorbell MMIO.
By sudoMike Lothian’s Vino series targets three dock generations as ordinary KMS devices, after earlier revisions never lit a panel.
By renderA 6.12 stable backport meant to wake nested USB3 devices is blamed for hard MCE resets when Android tooling hammers the root hub.
By kexecA 27-patch series hardens the emulated CCID device against out-of-bounds access, restores live migration, and makes it work with xHCI hosts.
By sudoUnchecked endpoint sizes and debug dumps left the Intel USB-to-I2C bridge open to memory corruption, hangs, and log leaks.
By kexec