Report: CVE-2026-5164 - Virtio-win: virtio-win: denial of service via unvalidated descriptor count in unm

Report: CVE-2026-5164 - Virtio-win: virtio-win: denial of service via unvalidated descriptor count in unm

CVE ID :CVE-2026-5164 Published : March 30, 2026, 3:02 p.m. | 22 minutes ago Description :A flaw was found in virtio-win. The `RhelDoUnMap()` function does not properly validate the number of descriptors provided by a user during an unmap request. A local user could exploit this input validation vulnerability by supplying an excessive number of descriptors, leading to a buffer overrun. This can cause a system crash, resulting in a Denial of Service (DoS). Severity: 6.7 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
MEDIUM
Published
March 30, 2026
Attack Vector: local
Impact: Denial of Service