A flaw was found in QEMU in the uefi-vars virtual device. When the guest writes to register UEFI_VARS_REG_BUFFER_SIZE, the .write callback `uefi_vars_write` is invoked. The function allocates a heap buffer without zeroing the memory, leaving the buffer filled with residual data from prior allocations. When the guest later reads from register UEFI_VARS_REG_PIO_BUFFER_TRANSFER, the .read callback `uefi_vars_read` returns leftover metadata or other sensitive process memory from the previously allocated buffer, leading to an information disclosure vulnerability.
Metrics
Affected Vendors & Products
References
History
Wed, 18 Feb 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | No description is available for this CVE. | A flaw was found in QEMU in the uefi-vars virtual device. When the guest writes to register UEFI_VARS_REG_BUFFER_SIZE, the .write callback `uefi_vars_write` is invoked. The function allocates a heap buffer without zeroing the memory, leaving the buffer filled with residual data from prior allocations. When the guest later reads from register UEFI_VARS_REG_PIO_BUFFER_TRANSFER, the .read callback `uefi_vars_read` returns leftover metadata or other sensitive process memory from the previously allocated buffer, leading to an information disclosure vulnerability. |
| Title | qemu-kvm: uefi-vars: information disclosure vulnerability in uefi_vars_write callback | Qemu-kvm: uefi-vars: information disclosure vulnerability in uefi_vars_write callback |
| First Time appeared |
Redhat
Redhat advanced Virtualization Redhat enterprise Linux Redhat openshift |
|
| CPEs | cpe:/a:redhat:advanced_virtualization:8::el8 cpe:/a:redhat:openshift:4 cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:6 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat advanced Virtualization Redhat enterprise Linux Redhat openshift |
|
| References |
|
Mon, 11 Aug 2025 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | No description is available for this CVE. | |
| Title | qemu-kvm: uefi-vars: information disclosure vulnerability in uefi_vars_write callback | |
| Weaknesses | CWE-212 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Status: PUBLISHED
Assigner: fedora
Published:
Updated: 2026-02-18T20:49:06.186Z
Reserved: 2025-08-11T09:40:17.260Z
Link: CVE-2025-8860
No data.
Status : Received
Published: 2026-02-18T21:16:22.260
Modified: 2026-02-18T21:16:22.260
Link: CVE-2025-8860
OpenCVE Enrichment
No data.