CVE-2014-3471Use After Free in Qemu

CWE-416Use After Free9 documents7 sources
Severity
5.5MEDIUMNVD
OSV7.5
EPSS
0.2%
top 63.88%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 12
Latest updateMay 14

Description

Use-after-free vulnerability in hw/pci/pcie.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a denial of service (QEMU instance crash) via hotplug and hotunplug operations of Virtio block devices.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages4 packages

debiandebian/qemu< qemu 2.1+dfsg-1 (bookworm)
Debianqemu/qemu< 2.1+dfsg-1+3
Ubuntuqemu/qemu< 2.0.0+dfsg-2ubuntu1.3
NVDqemu/qemu2.1.2+1

Patches

🔴Vulnerability Details

3
GHSA
GHSA-hfch-73vm-jx9g: Use-after-free vulnerability in hw/pci/pcie2022-05-14
OSV
CVE-2014-3471: Use-after-free vulnerability in hw/pci/pcie2018-01-12
OSV
qemu, qemu-kvm vulnerabilities2014-09-08

📋Vendor Advisories

3
Ubuntu
QEMU vulnerabilities2014-09-08
Red Hat
Qemu: hw: pci: use after free triggered via guest2014-06-23
Debian
CVE-2014-3471: qemu - Use-after-free vulnerability in hw/pci/pcie.c in QEMU (aka Quick Emulator) allow...2014

💬Community

2
Bugzilla
CVE-2014-3471 Qemu: hw: pci: use after free triggered via guest [fedora-all]2014-06-23
Bugzilla
CVE-2014-3471 Qemu: hw: pci: use after free triggered via guest2014-06-23