QEMU usb-ccid: out-of-bounds read

CVE-2026-18204

Public research by Warisjeet Singh sin99xx

Disclosed

The public finding

What was found.

A guest can fill the pending bulk-in ring, partially read a slot, then reuse it with a stale cursor. The unsigned length subtraction wraps and reads past data[].

Sources and evidence.

read the patch ↗