CVE-2025-54566 is a medium-severity vulnerability in QEMU through version 10.0.3, specifically within hw/pci/pcie_sriov.c, involving a migration state inconsistency related to CVE-2024-26327. This vulnerability has a CVSS score of 5.4, indicating an attack vector of adjacent network access with low attack complexity, requiring no user interaction, and potentially leading to low integrity and availability impacts. There is currently no evidence of active exploitation, no public exploit code available (Metasploit, Nuclei, ExploitDB), and minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 10.0.3CPE matchmatch criteria | cpe:2.3:a:qemu:qemu:*:*:*:*:*:*:*:* | ||
>= 10.0.0, <= 10.0.3CPE match | cpe:2.3:a:qemu:qemu:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.