Description
A flaw was found in QEMU. If the QIOChannelWebsock object is freed while it is waiting to complete a handshake, a GSource is leaked. This can lead to the callback firing later on and triggering a use-after-free in the use of the channel. This can be abused by a malicious client with network access to the VNC WebSocket port to cause a denial of service during the WebSocket handshake prior to the VNC client authentication.
References (11)
Core 11
Core References
Vendor Advisory vendor-advisory
x_refsource_redhat
https://access.redhat.com/errata/RHSA-2025:23228
Vendor Advisory vendor-advisory
x_refsource_redhat
https://access.redhat.com/errata/RHSA-2026:0326
Vendor Advisory vendor-advisory
x_refsource_redhat
https://access.redhat.com/errata/RHSA-2026:0332
Vendor Advisory vendor-advisory
x_refsource_redhat
https://access.redhat.com/errata/RHSA-2026:0702
Vendor Advisory vendor-advisory
x_refsource_redhat
https://access.redhat.com/errata/RHSA-2026:1831
Vendor Advisory vendor-advisory
x_refsource_redhat
RHSA-2026:18772
https://access.redhat.com/errata/RHSA-2026:18772
Vendor Advisory vendor-advisory
x_refsource_redhat
https://access.redhat.com/errata/RHSA-2026:3077
Vendor Advisory vendor-advisory
x_refsource_redhat
https://access.redhat.com/errata/RHSA-2026:3165
Vendor Advisory vendor-advisory
x_refsource_redhat
RHSA-2026:5578
https://access.redhat.com/errata/RHSA-2026:5578
Vendor Advisory vdb-entry
x_refsource_redhat
https://access.redhat.com/security/cve/CVE-2025-11234
Issue Tracking issue-tracking
x_refsource_redhat
https://bugzilla.redhat.com/show_bug.cgi?id=2401209
Scores
CVSS v3
7.5
EPSS
0.0016
EPSS Percentile
36.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-416
Status
published
Products (14)
Red Hat/Red Hat Enterprise Linux 10
18:10.0.0-14.el10_1.5
Red Hat/Red Hat Enterprise Linux 6
Red Hat/Red Hat Enterprise Linux 7
Red Hat/Red Hat Enterprise Linux 8
Red Hat/Red Hat Enterprise Linux 8
8100020251120003312.489197e6
Red Hat/Red Hat Enterprise Linux 8
8100020251202222937.489197e6
Red Hat/Red Hat Enterprise Linux 9
Red Hat/Red Hat Enterprise Linux 9
17:10.1.0-17.el9_8
Red Hat/Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
17:7.2.0-14.el9_2.24
Red Hat/Red Hat Enterprise Linux 9.4 Extended Update Support
17:8.2.0-11.el9_4.18
... and 4 more
Published
Oct 03, 2025
Tracked Since
Feb 18, 2026