A flaw was found in QEMU in the uefi-vars virtual device. When the guest writes to register UEFI_VARS_REG_BUFFER_SIZE, the .write callback `uefi_vars_write` is invoked. The function allocates a heap buffer without zeroing the memory, leaving the buffer filled with residual data from prior allocations. When the guest later reads from register UEFI_VARS_REG_PIO_BUFFER_TRANSFER, the .read callback `uefi_vars_read` returns leftover metadata or other sensitive process memory from the previously allocated buffer, leading to an information disclosure vulnerability.
History

Wed, 18 Feb 2026 21:00:00 +0000

Type Values Removed Values Added
Description No description is available for this CVE. A flaw was found in QEMU in the uefi-vars virtual device. When the guest writes to register UEFI_VARS_REG_BUFFER_SIZE, the .write callback `uefi_vars_write` is invoked. The function allocates a heap buffer without zeroing the memory, leaving the buffer filled with residual data from prior allocations. When the guest later reads from register UEFI_VARS_REG_PIO_BUFFER_TRANSFER, the .read callback `uefi_vars_read` returns leftover metadata or other sensitive process memory from the previously allocated buffer, leading to an information disclosure vulnerability.
Title qemu-kvm: uefi-vars: information disclosure vulnerability in uefi_vars_write callback Qemu-kvm: uefi-vars: information disclosure vulnerability in uefi_vars_write callback
First Time appeared Redhat
Redhat advanced Virtualization
Redhat enterprise Linux
Redhat openshift
CPEs cpe:/a:redhat:advanced_virtualization:8::el8
cpe:/a:redhat:openshift:4
cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat advanced Virtualization
Redhat enterprise Linux
Redhat openshift
References

Mon, 11 Aug 2025 12:30:00 +0000

Type Values Removed Values Added
Description No description is available for this CVE.
Title qemu-kvm: uefi-vars: information disclosure vulnerability in uefi_vars_write callback
Weaknesses CWE-212
References
Metrics threat_severity

None

cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

threat_severity

Low


cve-icon MITRE

Status: PUBLISHED

Assigner: fedora

Published:

Updated: 2026-02-18T20:49:06.186Z

Reserved: 2025-08-11T09:40:17.260Z

Link: CVE-2025-8860

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-02-18T21:16:22.260

Modified: 2026-02-18T21:16:22.260

Link: CVE-2025-8860

cve-icon Redhat

Severity : Low

Publid Date: 2025-08-11T00:00:00Z

Links: CVE-2025-8860 - Bugzilla

cve-icon OpenCVE Enrichment

No data.