Unrated severityNVD Advisory· Published Feb 11, 2020· Updated Aug 6, 2024
CVE-2014-0148
CVE-2014-0148
Description
Qemu before 2.0 block driver for Hyper-V VHDX Images is vulnerable to infinite loops and other potential issues when calculating BAT entries, due to missing bounds checks for block_size and logical_sector_size variables. These are used to derive other fields like 'sectors_per_block' etc. A user able to alter the Qemu disk image could ise this flaw to crash the Qemu instance resulting in DoS.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- rhn.redhat.com/errata/RHSA-2014-0420.htmlmitrex_refsource_MISC
- rhn.redhat.com/errata/RHSA-2014-0421.htmlmitrex_refsource_MISC
- www.openwall.com/lists/oss-security/2014/03/26/8mitrex_refsource_MISC
- bugzilla.redhat.com/show_bug.cgimitrex_refsource_MISC
- lists.gnu.org/archive/html/qemu-devel/2014-03/msg04994.htmlmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.