PoC Archive PoC Archive

tag

Qemu

  • CVE-2026-33317 binary HIGH 8.7

    OP-TEE PKCS#11 TA Out-of-Bounds Heap Write via `C_GetAttributeValue` (CVE-2026-33317)

    CVE-2026-33317 is missing bounds validation in entrygetattributevalue() in the OP-TEE PKCS#11 Trusted Application, reachable via the PKCS11CMDGETATTRIBUTEVALUE command. The TA does not verify that each attribute header and its associated data region lie fully…

    Patched 2026-07-05
  • None assigned as of 2026-07-03 binary CRITICAL

    QEMU CXL Type-3 Mailbox Guest-to-Host Escape

    QEMU's CXL Type-3 mailbox command handling contains two related out-of-bounds issues: the GETLOG handler validates offset + length as a byte range but then uses offset as an array index into cci->cellog, and the SETFEATURE rank-sparing handler copies…

    Unverified 2026-07-03
  • binary CRITICAL

    QEMUtiny - QEMU CXL Type-3 Memory Corruption Chain

    QEMUtiny is a memory corruption exploit chain in QEMU CXL Type-3 emulation that combines an out-of-bounds read (GETLOG) with an out-of-bounds write (SETFEATURE). The PoC leaks QEMU process pointers and then corrupts CXL device-adjacent state to steer…

    Unverified 2026-05-16