A QEMU guest display wrap is public, already fixed in 11.1.0
Brief
The reporter did not show a host crash or escape. ## Notes b8ef970532c30da2f3fa8985867a74f898ce96aa (Marc-André Lureau, 2026-08-04). Compute the blob scanout offset in 64-bit and reject a wrap. Resolves #3871. In v11.1.0 and v11.1.0-rc3.
Kind::Security, CVE::Assigned. No CVE id on the ticket or the commit. The reporter said they did not show a host crash or escape.
The 11.1 ChangeLog names a different virtio-gpu item (use-after-free CVE-2026-6502). It does not name #3871.
Do not invent a CVE. Do not republish the issue attachment.
Commit b8ef970532c30da2f3fa8985867a74f898ce96aa