CVE-2014-0146
published 2017-08-10CVE-2014-0146: The qcow2_open function in the (block/qcow2.c) in QEMU before 1.7.2 and 2.x before 2.0.0 allows local users to cause a denial of service (NULL pointer…
PriorityP415medium5.5CVSS 3.0
AVLACLPRNUIRSUCNINAH
EPSS
0.41%
33.2th percentile
The qcow2_open function in the (block/qcow2.c) in QEMU before 1.7.2 and 2.x before 2.0.0 allows local users to cause a denial of service (NULL pointer dereference) via a crafted image which causes an error, related to the initialization of the snapshot_offset and nb_snapshots fields.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | qemu | < qemu 2.0.0+dfsg-1 (bookworm) | qemu 2.0.0+dfsg-1 (bookworm) |
| qemu | qemu | <= 1.7.1 | — |
| qemu | qemu | — | — |
| qemu | qemu | >= 0 < 2.0.0+dfsg-1 | 2.0.0+dfsg-1 |
| qemu | qemu | >= 0 < 2.0.0+dfsg-1 | 2.0.0+dfsg-1 |
| qemu | qemu | >= 0 < 2.0.0+dfsg-1 | 2.0.0+dfsg-1 |
| qemu | qemu | >= 0 < 2.0.0+dfsg-1 | 2.0.0+dfsg-1 |
| qemu | qemu | >= 0 < 2.0.0+dfsg-2ubuntu1.3 | 2.0.0+dfsg-2ubuntu1.3 |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jfvf-g3qm-f87g: The qcow2_open function in the (block/qcow2
ghsa_unreviewed·2022-05-17
CVE-2014-0146 [MEDIUM] CWE-476 GHSA-jfvf-g3qm-f87g: The qcow2_open function in the (block/qcow2
The qcow2_open function in the (block/qcow2.c) in QEMU before 1.7.2 and 2.x before 2.0.0 allows local users to cause a denial of service (NULL pointer dereference) via a crafted image which causes an error, related to the initialization of the snapshot_offset and nb_snapshots fields.
OSV
CVE-2014-0146: The qcow2_open function in the (block/qcow2
osv·2017-08-10·CVSS 5.5
CVE-2014-0146 [MEDIUM] CVE-2014-0146: The qcow2_open function in the (block/qcow2
The qcow2_open function in the (block/qcow2.c) in QEMU before 1.7.2 and 2.x before 2.0.0 allows local users to cause a denial of service (NULL pointer dereference) via a crafted image which causes an error, related to the initialization of the snapshot_offset and nb_snapshots fields.
OSV
qemu, qemu-kvm vulnerabilities
osv·2014-09-08·CVSS 7.5
CVE-2013-4148 [HIGH] qemu, qemu-kvm vulnerabilities
qemu, qemu-kvm vulnerabilities
Michael S. Tsirkin, Anthony Liguori, and Michael Roth discovered multiple
issues with QEMU state loading after migration. An attacker able to modify
the state data could use these issues to cause a denial of service, or
possibly execute arbitrary code. (CVE-2013-4148, CVE-2013-4149,
CVE-2013-4150, CVE-2013-4151, CVE-2013-4526, CVE-2013-4527, CVE-2013-4529,
CVE-2013-4530, CVE-2013-4531, CVE-2013-4532, CVE-2013-4533, CVE-2013-4534,
CVE-2013-4535, CVE-2013-4536, CVE-2013-4537, CVE-2013-4538, CVE-2013-4539,
CVE-2013-4540, CVE-2013-4541, CVE-2013-4542, CVE-2013-6399, CVE-2014-0182,
CVE-2014-3461)
Kevin Wolf, Stefan Hajnoczi, Fam Zheng, Jeff Cody, Stefan Hajnoczi, and
others discovered multiple issues in the QEMU block drivers. An attacker
able to modify disk ima
Ubuntu
QEMU vulnerabilities
vendor_ubuntu·2014-09-08·CVSS 7.5
CVE-2013-4148 [HIGH] QEMU vulnerabilities
Title: QEMU vulnerabilities
Summary: Several security issues were fixed in QEMU.
Michael S. Tsirkin, Anthony Liguori, and Michael Roth discovered multiple
issues with QEMU state loading after migration. An attacker able to modify
the state data could use these issues to cause a denial of service, or
possibly execute arbitrary code. (CVE-2013-4148, CVE-2013-4149,
CVE-2013-4150, CVE-2013-4151, CVE-2013-4526, CVE-2013-4527, CVE-2013-4529,
CVE-2013-4530, CVE-2013-4531, CVE-2013-4532, CVE-2013-4533, CVE-2013-4534,
CVE-2013-4535, CVE-2013-4536, CVE-2013-4537, CVE-2013-4538, CVE-2013-4539,
CVE-2013-4540, CVE-2013-4541, CVE-2013-4542, CVE-2013-6399, CVE-2014-0182,
CVE-2014-3461)
Kevin Wolf, Stefan Hajnoczi, Fam Zheng, Jeff Cody, Stefan Hajnoczi, and
others discovered multiple issues in the QEMU
Red Hat
Qemu: qcow2: NULL dereference in qcow2_open() error path
vendor_redhat·2014-03-26·CVSS 5.5
CVE-2014-0146 [MEDIUM] CWE-476 Qemu: qcow2: NULL dereference in qcow2_open() error path
Qemu: qcow2: NULL dereference in qcow2_open() error path
The qcow2_open function in the (block/qcow2.c) in QEMU before 1.7.2 and 2.x before 2.0.0 allows local users to cause a denial of service (NULL pointer dereference) via a crafted image which causes an error, related to the initialization of the snapshot_offset and nb_snapshots fields.
Package: kvm (Red Hat Enterprise Linux 5) - Will not fix
Package: qemu-kvm (Red Hat Enterprise Linux 7) - Not affected
Package: qemu-kvm-rhev (Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse)) - Affected
Debian
CVE-2014-0146: qemu - The qcow2_open function in the (block/qcow2.c) in QEMU before 1.7.2 and 2.x befo...
vendor_debian·2014·CVSS 5.5
CVE-2014-0146 [MEDIUM] CVE-2014-0146: qemu - The qcow2_open function in the (block/qcow2.c) in QEMU before 1.7.2 and 2.x befo...
The qcow2_open function in the (block/qcow2.c) in QEMU before 1.7.2 and 2.x before 2.0.0 allows local users to cause a denial of service (NULL pointer dereference) via a crafted image which causes an error, related to the initialization of the snapshot_offset and nb_snapshots fields.
Scope: local
bookworm: resolved (fixed in 2.0.0+dfsg-1)
bullseye: resolved (fixed in 2.0.0+dfsg-1)
forky: resolved (fixed in 2.0.0+dfsg-1)
sid: resolved (fixed in 2.0.0+dfsg-1)
trixie: resolved (fixed in 2.0.0+dfsg-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-0146 Qemu: qcow2: NULL dereference in qcow2_open() error path [fedora-all]
bugzilla·2014-04-11·CVSS 5.5
CVE-2014-0146 [MEDIUM] CVE-2014-0146 Qemu: qcow2: NULL dereference in qcow2_open() error path [fedora-all]
CVE-2014-0146 Qemu: qcow2: NULL dereference in qcow2_open() error path [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this iss
Bugzilla
CVE-2014-0146 Qemu: qcow2: NULL dereference in qcow2_open() error path
bugzilla·2014-03-19·CVSS 5.5
CVE-2014-0146 [MEDIUM] CVE-2014-0146 Qemu: qcow2: NULL dereference in qcow2_open() error path
CVE-2014-0146 Qemu: qcow2: NULL dereference in qcow2_open() error path
Qemu block driver for the QCOW version 2 format is vulnerable to a NULL pointer
dereference flaw. It could occur in case of an error in reading a qcow2 image
file, after the 'snapshot_offset' & 'nb_snapshots' fields have been
initialised.
An user able to alter the Qemu disk image could use this flaw to crash the Qemu
instance resulting in Dos.
Upstream fix:
qcow2: Fix NULL dereference in qcow2_open() error path
-> http://git.qemu.org/?p=qemu.git;a=commit;h=11b128f4062dd7f89b14abc8877ff20d41b28be9
Discussion:
Acknowledgement:
This issue was discovered by Kevin Wolf of Red Hat Inc.
---
Created qemu tracking bugs for this issue:
Affects: fedora-all [bug 1086713]
---
This issue has been addressed in following pro
http://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=11b128f4062dd7f89b14abc8877ff20d41b28be9http://rhn.redhat.com/errata/RHSA-2014-0420.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0421.htmlhttp://www.debian.org/security/2014/dsa-3044http://www.openwall.com/lists/oss-security/2014/03/26/8https://bugzilla.redhat.com/show_bug.cgi?id=1078232http://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=11b128f4062dd7f89b14abc8877ff20d41b28be9http://rhn.redhat.com/errata/RHSA-2014-0420.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0421.htmlhttp://www.debian.org/security/2014/dsa-3044http://www.openwall.com/lists/oss-security/2014/03/26/8https://bugzilla.redhat.com/show_bug.cgi?id=1078232
2017-08-10
Published