PT-2024-6080 · Qemu+11 · Qemu+11

Mauro Matteo Cascella

·

Published

2024-04-11

·

Updated

2026-02-25

·

CVE-2024-4467

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions QEMU (affected versions not specified)
Description A flaw was found in the QEMU disk image utility (qemu-img) 'info' command. A specially crafted image file containing a json:{} value describing block devices in QMP could cause the qemu-img process on the host to consume large amounts of memory or CPU time, leading to denial of service or read/write to an existing external file. The vulnerability may allow an attacker to access confidential data, compromise its integrity, and cause a denial of service.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Resource Exhaustion

Memory Corruption

Weakness Enumeration

Related Identifiers

ALSA-2024:4278
ALSA-2024:4420
ALT-PU-2024-10230
ALT-PU-2024-10838
ALT-PU-2024-11120
AZL-60091
AZL-60922
BDU:2024-06923
CESA-2024_4420
CVE-2024-4467
INFSA-2024_4278
INFSA-2024_4420
MGASA-2024-0387
OESA-2024-1858
OPENSUSE-SU-2024:14411-1
OPENSUSE-SU-2024_2977-1
OPENSUSE-SU-2024_2983-1
OPENSUSE-SU-2024_3077-1
OPENSUSE-SU-2024_3396-1
RHSA-2024:4276
RHSA-2024:4277
RHSA-2024:4278
RHSA-2024:4372
RHSA-2024:4373
RHSA-2024:4374
RHSA-2024:4420
RHSA-2024:4724
RHSA-2024:4727
RHSA-2024_4278
RHSA-2024_4420
SUSE-SU-2024:2977-1
SUSE-SU-2024:2983-1
SUSE-SU-2024:3077-1
SUSE-SU-2024:3396-1
SUSE-SU-2024_2983-1
SUSE-SU-2024_3077-1
SUSE-SU-2024_3396-1
SUSE-SU-2025:20036-1
USN-7744-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Debian
Linuxmint
Qemu
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu