cbcvebase.
CVE-2014-0147
published 2022-09-29

CVE-2014-0147: Qemu before 1.6.2 block diver for the various disk image formats used by Bochs and for the QCOW version 2 format, are vulnerable to a possible crash caused by…

PriorityP422medium6.2CVSS 3.1
AVLACLPRNUINSUCNINAH
EPSS
0.33%
25.0th percentile
Qemu before 1.6.2 block diver for the various disk image formats used by Bochs and for the QCOW version 2 format, are vulnerable to a possible crash caused by signed data types or a logic error while creating QCOW2 snapshots, which leads to incorrectly calling update_refcount() routine.

Affected

17 ranges
VendorProductVersion rangeFixed in
debianqemu< qemu 2.0.0+dfsg-1 (bookworm)qemu 2.0.0+dfsg-1 (bookworm)
fedoraprojectfedora
qemuqemu< 1.6.21.6.2
qemuqemu
qemuqemu>= 0 < 2.0.0+dfsg-12.0.0+dfsg-1
qemuqemu>= 0 < 2.0.0+dfsg-12.0.0+dfsg-1
qemuqemu>= 0 < 2.0.0+dfsg-12.0.0+dfsg-1
qemuqemu>= 0 < 2.0.0+dfsg-12.0.0+dfsg-1
qemuqemu>= 0 < 2.0.0+dfsg-2ubuntu1.32.0.0+dfsg-2ubuntu1.3
redhatenterprise_linux_desktop
redhatenterprise_linux_eus
redhatenterprise_linux_openstack_platform
redhatenterprise_linux_server
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_tus
redhatenterprise_linux_workstation
redhatvirtualization

CVSS provenance

nvdv3.16.2MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian6.2MEDIUM
vendor_redhat6.2MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.