A flaw was found in QEMU. A specially crafted VMDK image could trigger an out-of-bounds read vulnerability, potentially leading to a 12-byte leak of sensitive information or a denial of service condition (DoS).
https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-7806