CVE-2014-2894Improper Restriction of Operations within the Bounds of a Memory Buffer in Qemu

Severity
7.2HIGHNVD
OSV4.9
EPSS
0.1%
top 81.60%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 23
Latest updateMay 13

Description

Off-by-one error in the cmd_smart function in the smart self test in hw/ide/core.c in QEMU before 2.0 allows local users to have unspecified impact via a SMART EXECUTE OFFLINE command that triggers a buffer underflow and memory corruption.

CVSS vector

AV:L/AC:L/C:C/I:C/A:CExploitability: 3.9 | Impact: 10.0

Affected Packages4 packages

debiandebian/qemu< qemu 2.0.0+dfsg-1 (bookworm)
Debianqemu/qemu< 2.0.0+dfsg-1+3
Ubuntuqemu/qemu< 2.0.0~rc1+dfsg-0ubuntu3.1
NVDqemu/qemu1.7.1+74

🔴Vulnerability Details

3
GHSA
GHSA-5v9x-x46w-vf3f: Off-by-one error in the cmd_smart function in the smart self test in hw/ide/core2022-05-13
OSV
qemu, qemu-kvm vulnerabilities2014-04-28
OSV
CVE-2014-2894: Off-by-one error in the cmd_smart function in the smart self test in hw/ide/core2014-04-23

📋Vendor Advisories

3
Ubuntu
QEMU vulnerabilities2014-04-28
Red Hat
QEMU: out of bounds buffer accesses, guest triggerable via IDE SMART2014-04-14
Debian
CVE-2014-2894: qemu - Off-by-one error in the cmd_smart function in the smart self test in hw/ide/core...2014

💬Community

2
Bugzilla
CVE-2014-2894 QEMU: out of bounds buffer accesses, guest triggerable via IDE SMART [fedora-all]2014-04-15
Bugzilla
CVE-2014-2894 QEMU: out of bounds buffer accesses, guest triggerable via IDE SMART2014-04-15