QEMU usb-ccid: out-of-bounds read
CVE-2026-18204
Public research by Warisjeet Singh sin99xx
Disclosed
The public finding
What was found.
A guest can fill the pending bulk-in ring, partially read a slot, then reuse it with a stale cursor. The unsigned length subtraction wraps and reads past data[].