CVE-2014-0148
published 2022-09-29CVE-2014-0148: Qemu before 2.0 block driver for Hyper-V VHDX Images is vulnerable to infinite loops and other potential issues when calculating BAT entries, due to missing…
PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.30%
22.7th percentile
Qemu before 2.0 block driver for Hyper-V VHDX Images is vulnerable to infinite loops and other potential issues when calculating BAT entries, due to missing bounds checks for block_size and logical_sector_size variables. These are used to derive other fields like 'sectors_per_block' etc. A user able to alter the Qemu disk image could ise this flaw to crash the Qemu instance resulting in DoS.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | qemu | < qemu 2.0.0+dfsg-1 (bookworm) | qemu 2.0.0+dfsg-1 (bookworm) |
| qemu | qemu | < 2.0.0 | 2.0.0 |
| qemu | qemu | — | — |
| qemu | qemu | >= 0 < 2.0.0+dfsg-1 | 2.0.0+dfsg-1 |
| qemu | qemu | >= 0 < 2.0.0+dfsg-1 | 2.0.0+dfsg-1 |
| qemu | qemu | >= 0 < 2.0.0+dfsg-1 | 2.0.0+dfsg-1 |
| qemu | qemu | >= 0 < 2.0.0+dfsg-1 | 2.0.0+dfsg-1 |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_openstack_platform | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | virtualization | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Qemu: vhdx: bounds checking for block_size and logical_sector_size
vendor_redhat·2014-03-26·CVSS 5.5
CVE-2014-0148 [MEDIUM] Qemu: vhdx: bounds checking for block_size and logical_sector_size
Qemu: vhdx: bounds checking for block_size and logical_sector_size
Qemu before 2.0 block driver for Hyper-V VHDX Images is vulnerable to infinite loops and other potential issues when calculating BAT entries, due to missing bounds checks for block_size and logical_sector_size variables. These are used to derive other fields like 'sectors_per_block' etc. A user able to alter the Qemu disk image could ise this flaw to crash the Qemu instance resulting in DoS.
Statement: This issue does not affect the versions of kvm package as shipped with Red Hat
Enterprise Linux 5.
This issue affects the versions of qemu-kvm package as shipped with Red Hat
Enterprise Linux 6.
Package: kvm (Red Hat Enterprise Linux 5) - Not affected
Package: qemu-kvm (Red Hat Enterprise Linux 7) - Not affected
Package:
Debian
CVE-2014-0148: qemu - Qemu before 2.0 block driver for Hyper-V VHDX Images is vulnerable to infinite l...
vendor_debian·2014·CVSS 5.5
CVE-2014-0148 [MEDIUM] CVE-2014-0148: qemu - Qemu before 2.0 block driver for Hyper-V VHDX Images is vulnerable to infinite l...
Qemu before 2.0 block driver for Hyper-V VHDX Images is vulnerable to infinite loops and other potential issues when calculating BAT entries, due to missing bounds checks for block_size and logical_sector_size variables. These are used to derive other fields like 'sectors_per_block' etc. A user able to alter the Qemu disk image could ise this flaw to crash the Qemu instance resulting in DoS.
Scope: local
bookworm: resolved (fixed in 2.0.0+dfsg-1)
bullseye: resolved (fixed in 2.0.0+dfsg-1)
forky: resolved (fixed in 2.0.0+dfsg-1)
sid: resolved (fixed in 2.0.0+dfsg-1)
trixie: resolved (fixed in 2.0.0+dfsg-1)
GHSA
GHSA-jh89-xppm-m3xg: Qemu before 2
ghsa_unreviewed·2022-09-30
CVE-2014-0148 [MEDIUM] CWE-835 GHSA-jh89-xppm-m3xg: Qemu before 2
Qemu before 2.0 block driver for Hyper-V VHDX Images is vulnerable to infinite loops and other potential issues when calculating BAT entries, due to missing bounds checks for block_size and logical_sector_size variables. These are used to derive other fields like 'sectors_per_block' etc. A user able to alter the Qemu disk image could ise this flaw to crash the Qemu instance resulting in DoS.
OSV
CVE-2014-0148: Qemu before 2
osv·2022-09-29·CVSS 5.5
CVE-2014-0148 [MEDIUM] CVE-2014-0148: Qemu before 2
Qemu before 2.0 block driver for Hyper-V VHDX Images is vulnerable to infinite loops and other potential issues when calculating BAT entries, due to missing bounds checks for block_size and logical_sector_size variables. These are used to derive other fields like 'sectors_per_block' etc. A user able to alter the Qemu disk image could ise this flaw to crash the Qemu instance resulting in DoS.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-0148 Qemu: vhdx: bounds checking for block_size and logical_sector_size [fedora-all]
bugzilla·2014-04-11·CVSS 5.5
CVE-2014-0148 [MEDIUM] CVE-2014-0148 Qemu: vhdx: bounds checking for block_size and logical_sector_size [fedora-all]
CVE-2014-0148 Qemu: vhdx: bounds checking for block_size and logical_sector_size [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note
Bugzilla
CVE-2014-0148 Qemu: vhdx: bounds checking for block_size and logical_sector_size
bugzilla·2014-03-19·CVSS 5.5
CVE-2014-0148 [MEDIUM] CVE-2014-0148 Qemu: vhdx: bounds checking for block_size and logical_sector_size
CVE-2014-0148 Qemu: vhdx: bounds checking for block_size and logical_sector_size
Qemu block driver for Hyper-V VHDX Images is vulnerable to infinite loops and
other potential issues when calculating BAT entries, due to missing bounds
checks for block_size and logical_sector_size variables. These are used to
derive other fields like 'sectors_per_block' etc.
An user able to alter the Qemu disk image could ise this flaw to crash the Qemu instance resulting in DoS.
Upstream fix:
vhdx: Bounds checking for block_size and logical_sector_size
-> http://git.qemu.org/?p=qemu.git;a=commit;h=1d7678dec4761acdc43439da6ceda41a703ba1a6
Discussion:
Statement:
This issue does not affect the versions of kvm package as shipped with Red Hat
Enterprise Linux 5.
This issue affects the versions of qemu-kvm
http://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=1d7678dec4761acdc43439da6ceda41a703ba1a6http://rhn.redhat.com/errata/RHSA-2014-0420.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0421.htmlhttp://www.openwall.com/lists/oss-security/2014/03/26/8https://bugzilla.redhat.com/show_bug.cgi?id=1078212https://lists.gnu.org/archive/html/qemu-devel/2014-03/msg04994.htmlhttp://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=1d7678dec4761acdc43439da6ceda41a703ba1a6http://rhn.redhat.com/errata/RHSA-2014-0420.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0421.htmlhttp://www.openwall.com/lists/oss-security/2014/03/26/8https://bugzilla.redhat.com/show_bug.cgi?id=1078212https://lists.gnu.org/archive/html/qemu-devel/2014-03/msg04994.html
2022-09-29
Published