CVE-2014-2894
published 2014-04-23CVE-2014-2894: Off-by-one error in the cmd_smart function in the smart self test in hw/ide/core.c in QEMU before 2.0 allows local users to have unspecified impact via a SMART…
PriorityP425high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.39%
31.2th percentile
Off-by-one error in the cmd_smart function in the smart self test in hw/ide/core.c in QEMU before 2.0 allows local users to have unspecified impact via a SMART EXECUTE OFFLINE command that triggers a buffer underflow and memory corruption.
Affected
81 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | qemu | < qemu 2.0.0+dfsg-1 (bookworm) | qemu 2.0.0+dfsg-1 (bookworm) |
| qemu | qemu | <= 1.7.1 | — |
| qemu | qemu | — | — |
| qemu | qemu | — | — |
| qemu | qemu | — | — |
| qemu | qemu | — | — |
| qemu | qemu | — | — |
| qemu | qemu | — | — |
| qemu | qemu | — | — |
| qemu | qemu | — | — |
| qemu | qemu | — | — |
| qemu | qemu | — | — |
| qemu | qemu | — | — |
| qemu | qemu | — | — |
| qemu | qemu | — | — |
| qemu | qemu | — | — |
| qemu | qemu | — | — |
| qemu | qemu | — | — |
| qemu | qemu | — | — |
| qemu | qemu | — | — |
| qemu | qemu | — | — |
| qemu | qemu | — | — |
| qemu | qemu | — | — |
| qemu | qemu | — | — |
| qemu | qemu | — | — |
CVSS provenance
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.2HIGH
vendor_debian7.2HIGH
vendor_redhat7.2HIGH
vendor_ubuntu4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5v9x-x46w-vf3f: Off-by-one error in the cmd_smart function in the smart self test in hw/ide/core
ghsa_unreviewed·2022-05-13
CVE-2014-2894 [HIGH] GHSA-5v9x-x46w-vf3f: Off-by-one error in the cmd_smart function in the smart self test in hw/ide/core
Off-by-one error in the cmd_smart function in the smart self test in hw/ide/core.c in QEMU before 2.0 allows local users to have unspecified impact via a SMART EXECUTE OFFLINE command that triggers a buffer underflow and memory corruption.
OSV
qemu, qemu-kvm vulnerabilities
osv·2014-04-28·CVSS 4.9
CVE-2013-4544 [MEDIUM] qemu, qemu-kvm vulnerabilities
qemu, qemu-kvm vulnerabilities
Michael S. Tsirkin discovered that QEMU incorrectly handled vmxnet3
devices. A local guest could possibly use this issue to cause a denial of
service, or possibly execute arbitrary code on the host. This issue only
applied to Ubuntu 13.10 and Ubuntu 14.04 LTS. (CVE-2013-4544)
Michael S. Tsirkin discovered that QEMU incorrectly handled virtio-net
MAC addresses. A local guest could possibly use this issue to cause a
denial of service, or possibly execute arbitrary code on the host.
(CVE-2014-0150)
Benoît Canet discovered that QEMU incorrectly handled SMART self-tests. A
local guest could possibly use this issue to cause a denial of service, or
possibly execute arbitrary code on the host. (CVE-2014-2894)
OSV
CVE-2014-2894: Off-by-one error in the cmd_smart function in the smart self test in hw/ide/core
osv·2014-04-23·CVSS 7.2
CVE-2014-2894 [HIGH] CVE-2014-2894: Off-by-one error in the cmd_smart function in the smart self test in hw/ide/core
Off-by-one error in the cmd_smart function in the smart self test in hw/ide/core.c in QEMU before 2.0 allows local users to have unspecified impact via a SMART EXECUTE OFFLINE command that triggers a buffer underflow and memory corruption.
Ubuntu
QEMU vulnerabilities
vendor_ubuntu·2014-04-28·CVSS 4.9
CVE-2013-4544 [MEDIUM] QEMU vulnerabilities
Title: QEMU vulnerabilities
Summary: Several security issues were fixed in QEMU.
Michael S. Tsirkin discovered that QEMU incorrectly handled vmxnet3
devices. A local guest could possibly use this issue to cause a denial of
service, or possibly execute arbitrary code on the host. This issue only
applied to Ubuntu 13.10 and Ubuntu 14.04 LTS. (CVE-2013-4544)
Michael S. Tsirkin discovered that QEMU incorrectly handled virtio-net
MAC addresses. A local guest could possibly use this issue to cause a
denial of service, or possibly execute arbitrary code on the host.
(CVE-2014-0150)
Benoît Canet discovered that QEMU incorrectly handled SMART self-tests. A
local guest could possibly use this issue to cause a denial of service, or
possibly execute arbitrary code on the host. (CVE-2014-2894)
Ins
Red Hat
QEMU: out of bounds buffer accesses, guest triggerable via IDE SMART
vendor_redhat·2014-04-14·CVSS 7.2
CVE-2014-2894 [HIGH] CWE-119 QEMU: out of bounds buffer accesses, guest triggerable via IDE SMART
QEMU: out of bounds buffer accesses, guest triggerable via IDE SMART
Off-by-one error in the cmd_smart function in the smart self test in hw/ide/core.c in QEMU before 2.0 allows local users to have unspecified impact via a SMART EXECUTE OFFLINE command that triggers a buffer underflow and memory corruption.
Statement: This issue does not affect the versions of kvm package as shipped with Red Hat
Enterprise Linux 5.
Package: kvm (Red Hat Enterprise Linux 5) - Not affected
Package: qemu-kvm-rhev (Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse)) - Affected
Debian
CVE-2014-2894: qemu - Off-by-one error in the cmd_smart function in the smart self test in hw/ide/core...
vendor_debian·2014·CVSS 7.2
CVE-2014-2894 [HIGH] CVE-2014-2894: qemu - Off-by-one error in the cmd_smart function in the smart self test in hw/ide/core...
Off-by-one error in the cmd_smart function in the smart self test in hw/ide/core.c in QEMU before 2.0 allows local users to have unspecified impact via a SMART EXECUTE OFFLINE command that triggers a buffer underflow and memory corruption.
Scope: local
bookworm: resolved (fixed in 2.0.0+dfsg-1)
bullseye: resolved (fixed in 2.0.0+dfsg-1)
forky: resolved (fixed in 2.0.0+dfsg-1)
sid: resolved (fixed in 2.0.0+dfsg-1)
trixie: resolved (fixed in 2.0.0+dfsg-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-2894 QEMU: out of bounds buffer accesses, guest triggerable via IDE SMART [fedora-all]
bugzilla·2014-04-15·CVSS 7.2
CVE-2014-2894 [HIGH] CVE-2014-2894 QEMU: out of bounds buffer accesses, guest triggerable via IDE SMART [fedora-all]
CVE-2014-2894 QEMU: out of bounds buffer accesses, guest triggerable via IDE SMART [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please no
Bugzilla
CVE-2014-2894 QEMU: out of bounds buffer accesses, guest triggerable via IDE SMART
bugzilla·2014-04-15·CVSS 7.2
CVE-2014-2894 [HIGH] CVE-2014-2894 QEMU: out of bounds buffer accesses, guest triggerable via IDE SMART
CVE-2014-2894 QEMU: out of bounds buffer accesses, guest triggerable via IDE SMART
An out of bounds memory access flaw was found in Qemu's IDE device model.
It leads to Qemu's memory corruption via buffer overwrite(4 bytes). It occurs
while executing IDE SMART commands.
A privileged guest user could use this flaw to corrupt qemu process' memory on the host, which could potentially result in arbitrary code execution on the host with the privileges of the qemu process.
Upstream fix:
-> https://lists.nongnu.org/archive/html/qemu-devel/2014-04/msg02016.html
Discussion:
Statement:
This issue does not affect the versions of kvm package as shipped with Red Hat
Enterprise Linux 5.
---
Created qemu tracking bugs for this issue:
Affects: fedora-all [bug 1087981]
---
Upstream commit:
http
http://rhn.redhat.com/errata/RHSA-2014-0704.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0743.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0744.htmlhttp://secunia.com/advisories/57945http://secunia.com/advisories/58191http://www.openwall.com/lists/oss-security/2014/04/15/4http://www.openwall.com/lists/oss-security/2014/04/18/5http://www.securityfocus.com/bid/66932http://www.ubuntu.com/usn/USN-2182-1https://lists.nongnu.org/archive/html/qemu-devel/2014-04/msg02016.htmlhttps://lists.nongnu.org/archive/html/qemu-devel/2014-04/msg02095.htmlhttps://lists.nongnu.org/archive/html/qemu-devel/2014-04/msg02152.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0704.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0743.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0744.htmlhttp://secunia.com/advisories/57945http://secunia.com/advisories/58191http://www.openwall.com/lists/oss-security/2014/04/15/4http://www.openwall.com/lists/oss-security/2014/04/18/5http://www.securityfocus.com/bid/66932http://www.ubuntu.com/usn/USN-2182-1https://lists.nongnu.org/archive/html/qemu-devel/2014-04/msg02016.htmlhttps://lists.nongnu.org/archive/html/qemu-devel/2014-04/msg02095.htmlhttps://lists.nongnu.org/archive/html/qemu-devel/2014-04/msg02152.html
2014-04-23
Published