Unrated severityNVD Advisory· Published Nov 15, 2014· Updated May 6, 2026
CVE-2014-5388
CVE-2014-5388
Description
Off-by-one error in the pci_read function in the ACPI PCI hotplug interface (hw/acpi/pcihp.c) in QEMU allows local guest users to obtain sensitive information and have other unspecified impact related to a crafted PCI device that triggers memory corruption.
Affected products
5cpe:2.3:o:canonical:ubuntu_linux:10.04:*:*:*:-:*:*:*+ 3 more
- cpe:2.3:o:canonical:ubuntu_linux:10.04:*:*:*:-:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:14.10:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- seclists.org/oss-sec/2014/q3/438nvdMailing ListPatchThird Party Advisory
- lists.gnu.org/archive/html/qemu-devel/2014-08/msg03338.htmlnvdPatchThird Party Advisory
- seclists.org/oss-sec/2014/q3/440nvdMailing ListThird Party Advisory
- www.ubuntu.com/usn/USN-2409-1nvdThird Party Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingThird Party Advisory
News mentions
0No linked articles in our index yet.