#VU116886 Use-after-free in QEMU - CVE-2025-11234
Published: October 10, 2025
QEMU
QEMU
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a use-after-free error in websocket handshake code in /io/channel-websock.c. A remote attacker with network access to the VNC WebSocket port can perform a denial of service during the WebSocket handshake prior to the VNC client authentication.