Unrated severityNVD Advisory· Published Oct 6, 2014· Updated May 6, 2026
CVE-2014-3633
CVE-2014-3633
Description
The qemuDomainGetBlockIoTune function in qemu/qemu_driver.c in libvirt before 1.2.9, when a disk has been hot-plugged or removed from the live image, allows remote attackers to cause a denial of service (crash) or read sensitive heap information via a crafted blkiotune query, which triggers an out-of-bounds read.
Affected products
12cpe:2.3:a:libvirt:libvirt:*:*:*:*:*:*:*:*+ 8 more
- cpe:2.3:a:libvirt:libvirt:*:*:*:*:*:*:*:*range: <=1.2.8
- cpe:2.3:a:libvirt:libvirt:1.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:libvirt:libvirt:1.2.1:*:*:*:*:*:*:*
- cpe:2.3:a:libvirt:libvirt:1.2.2:*:*:*:*:*:*:*
- cpe:2.3:a:libvirt:libvirt:1.2.3:*:*:*:*:*:*:*
- cpe:2.3:a:libvirt:libvirt:1.2.4:*:*:*:*:*:*:*
- cpe:2.3:a:libvirt:libvirt:1.2.5:*:*:*:*:*:*:*
- cpe:2.3:a:libvirt:libvirt:1.2.6:*:*:*:*:*:*:*
- cpe:2.3:a:libvirt:libvirt:1.2.7:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:10.04:*:lts:*:*:*:*:*+ 2 more
- cpe:2.3:o:canonical:ubuntu_linux:10.04:*:lts:*:*:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:12.04:*:lts:*:*:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
10- security.libvirt.org/2014/0004.htmlnvdVendor Advisory
- libvirt.org/git/nvd
- lists.opensuse.org/opensuse-updates/2014-10/msg00014.htmlnvd
- lists.opensuse.org/opensuse-updates/2014-10/msg00017.htmlnvd
- rhn.redhat.com/errata/RHSA-2014-1352.htmlnvd
- secunia.com/advisories/60291nvd
- secunia.com/advisories/60895nvd
- security.gentoo.org/glsa/glsa-201412-04.xmlnvd
- www.debian.org/security/2014/dsa-3038nvd
- www.ubuntu.com/usn/USN-2366-1nvd
News mentions
0No linked articles in our index yet.