QEMU fixes three CVEs in USB smartcard reader emulation
Guest-triggerable crashes and an out-of-bounds read in the CCID device land alongside broader protocol and migration hardening.
QEMU's USB CCID smartcard reader emulation is receiving fixes for three security flaws that let a guest crash the emulator or read out of bounds, along with a wider cleanup of specification compliance and I/O handling.
Marc-André Lureau prepared the work. CVE-2026-18609 is a guest-triggered assertion failure on a short interrupt transfer. CVE-2026-18204 is an out-of-bounds read from the pending bulk-in ring buffer. CVE-2026-18410 is an assertion crash when the pending answers ring overflows. The assertion bugs are straightforward denial-of-service paths against the hypervisor process from inside the guest.
The same series also hardens response sizing so an oversized payload from a card backend cannot overrun fixed bulk-in buffers (a backend issue rather than a guest one, but still a real memory-safety gap). Bulk-in delivery is corrected for xHCI, which can present transfers larger than the endpoint's 64-byte maximum and previously left completed responses stranded, blocking later smartcard traffic. Live migration is blocked while queues still hold pending data, and the migration stream is extended so in-flight answers are no longer silently lost on older state formats.
Protocol behavior moves closer to the CCID specification: unsupported Secure, Escape, and clock/rate commands now return the mandated response types; commands aimed at non-existent slots are rejected; per-command length checks stop stale buffer contents from being treated as payload; missing-card APDU paths report the required failure status; and descriptors stop advertising PIN verification or omitting T=1 when the implementation did not match. Compatibility properties preserve prior descriptor and migration behavior for older machine types.
Smartcard passthrough and emulation matter in enterprise guests that rely on hardware tokens for authentication. Guest-triggerable emulator crashes and incorrect CCID framing both undermine that path: one takes down the host-side process, the other breaks real middleware that expects a standards-conformant reader.