PT-2020-7590 · Qemu+3 · Qemu+3

Jeff Cody

·

Published

2014-04-22

·

Updated

2023-02-13

·

CVE-2014-0148

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Qemu versions prior to 2.0
Description The issue arises from missing bounds checks for block size and logical sector size variables in the block driver for Hyper-V VHDX Images. This could lead to infinite loops and other potential issues when calculating BAT entries, which are used to derive other fields like sectors per block. A user who can alter the Qemu disk image could exploit this flaw to crash the Qemu instance, resulting in a denial of service (DoS).
Recommendations For Qemu versions prior to 2.0, update to version 2.0 or later to resolve the issue.

Fix

DoS

Infinite Loop

Weakness Enumeration

Related Identifiers

ALT-PU-2014-1526
CESA-2014_0420
CVE-2014-0148
MGASA-2014-0426
RHSA-2014:0420
RHSA-2014:0421
RHSA-2014:0434
RHSA-2014:0435
RHSA-2014:0674
RHSA-2014_0420

Affected Products

Alt Linux
Centos
Qemu
Red Hat