CVE-2014-3471
published 2018-01-12CVE-2014-3471: Use-after-free vulnerability in hw/pci/pcie.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a denial of service (QEMU instance crash) via…
PriorityP419medium5.5CVSS 3.0
AVLACLPRLUINSUCNINAH
EPSS
0.40%
32.2th percentile
Use-after-free vulnerability in hw/pci/pcie.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a denial of service (QEMU instance crash) via hotplug and hotunplug operations of Virtio block devices.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | qemu | < qemu 2.1+dfsg-1 (bookworm) | qemu 2.1+dfsg-1 (bookworm) |
| qemu | qemu | <= 2.1.2 | — |
| qemu | qemu | — | — |
| qemu | qemu | >= 0 < 2.1+dfsg-1 | 2.1+dfsg-1 |
| qemu | qemu | >= 0 < 2.1+dfsg-1 | 2.1+dfsg-1 |
| qemu | qemu | >= 0 < 2.1+dfsg-1 | 2.1+dfsg-1 |
| qemu | qemu | >= 0 < 2.1+dfsg-1 | 2.1+dfsg-1 |
| qemu | qemu | >= 0 < 2.0.0+dfsg-2ubuntu1.3 | 2.0.0+dfsg-2ubuntu1.3 |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
QEMU vulnerabilities
vendor_ubuntu·2014-09-08·CVSS 7.5
CVE-2013-4148 [HIGH] QEMU vulnerabilities
Title: QEMU vulnerabilities
Summary: Several security issues were fixed in QEMU.
Michael S. Tsirkin, Anthony Liguori, and Michael Roth discovered multiple
issues with QEMU state loading after migration. An attacker able to modify
the state data could use these issues to cause a denial of service, or
possibly execute arbitrary code. (CVE-2013-4148, CVE-2013-4149,
CVE-2013-4150, CVE-2013-4151, CVE-2013-4526, CVE-2013-4527, CVE-2013-4529,
CVE-2013-4530, CVE-2013-4531, CVE-2013-4532, CVE-2013-4533, CVE-2013-4534,
CVE-2013-4535, CVE-2013-4536, CVE-2013-4537, CVE-2013-4538, CVE-2013-4539,
CVE-2013-4540, CVE-2013-4541, CVE-2013-4542, CVE-2013-6399, CVE-2014-0182,
CVE-2014-3461)
Kevin Wolf, Stefan Hajnoczi, Fam Zheng, Jeff Cody, Stefan Hajnoczi, and
others discovered multiple issues in the QEMU
Red Hat
Qemu: hw: pci: use after free triggered via guest
vendor_redhat·2014-06-23·CVSS 5.5
CVE-2014-3471 [MEDIUM] CWE-416 Qemu: hw: pci: use after free triggered via guest
Qemu: hw: pci: use after free triggered via guest
Use-after-free vulnerability in hw/pci/pcie.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a denial of service (QEMU instance crash) via hotplug and hotunplug operations of Virtio block devices.
Statement: This issue does not affect the versions of kvm package as shipped with Red Hat
Enterprise Linux 5.
This issue does not affect the versions of qemu-kvm package as shipped with Red Hat Enterprise Linux 6.
This issue does not affect the versions of qemu-kvm package as shipped with Red Hat Enterprise Linux 7.
Package: kvm (Red Hat Enterprise Linux 5) - Not affected
Package: qemu-kvm (Red Hat Enterprise Linux 6) - Not affected
Package: qemu-kvm (Red Hat Enterprise Linux 7) - Not affected
Package: qemu-kvm-rhev (Red H
Debian
CVE-2014-3471: qemu - Use-after-free vulnerability in hw/pci/pcie.c in QEMU (aka Quick Emulator) allow...
vendor_debian·2014·CVSS 5.5
CVE-2014-3471 [MEDIUM] CVE-2014-3471: qemu - Use-after-free vulnerability in hw/pci/pcie.c in QEMU (aka Quick Emulator) allow...
Use-after-free vulnerability in hw/pci/pcie.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a denial of service (QEMU instance crash) via hotplug and hotunplug operations of Virtio block devices.
Scope: local
bookworm: resolved (fixed in 2.1+dfsg-1)
bullseye: resolved (fixed in 2.1+dfsg-1)
forky: resolved (fixed in 2.1+dfsg-1)
sid: resolved (fixed in 2.1+dfsg-1)
trixie: resolved (fixed in 2.1+dfsg-1)
GHSA
GHSA-hfch-73vm-jx9g: Use-after-free vulnerability in hw/pci/pcie
ghsa_unreviewed·2022-05-14
CVE-2014-3471 [MEDIUM] CWE-416 GHSA-hfch-73vm-jx9g: Use-after-free vulnerability in hw/pci/pcie
Use-after-free vulnerability in hw/pci/pcie.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a denial of service (QEMU instance crash) via hotplug and hotunplug operations of Virtio block devices.
OSV
CVE-2014-3471: Use-after-free vulnerability in hw/pci/pcie
osv·2018-01-12·CVSS 5.5
CVE-2014-3471 [MEDIUM] CVE-2014-3471: Use-after-free vulnerability in hw/pci/pcie
Use-after-free vulnerability in hw/pci/pcie.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a denial of service (QEMU instance crash) via hotplug and hotunplug operations of Virtio block devices.
OSV
qemu, qemu-kvm vulnerabilities
osv·2014-09-08·CVSS 7.5
CVE-2013-4148 [HIGH] qemu, qemu-kvm vulnerabilities
qemu, qemu-kvm vulnerabilities
Michael S. Tsirkin, Anthony Liguori, and Michael Roth discovered multiple
issues with QEMU state loading after migration. An attacker able to modify
the state data could use these issues to cause a denial of service, or
possibly execute arbitrary code. (CVE-2013-4148, CVE-2013-4149,
CVE-2013-4150, CVE-2013-4151, CVE-2013-4526, CVE-2013-4527, CVE-2013-4529,
CVE-2013-4530, CVE-2013-4531, CVE-2013-4532, CVE-2013-4533, CVE-2013-4534,
CVE-2013-4535, CVE-2013-4536, CVE-2013-4537, CVE-2013-4538, CVE-2013-4539,
CVE-2013-4540, CVE-2013-4541, CVE-2013-4542, CVE-2013-6399, CVE-2014-0182,
CVE-2014-3461)
Kevin Wolf, Stefan Hajnoczi, Fam Zheng, Jeff Cody, Stefan Hajnoczi, and
others discovered multiple issues in the QEMU block drivers. An attacker
able to modify disk ima
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-3471 Qemu: hw: pci: use after free triggered via guest [fedora-all]
bugzilla·2014-06-23·CVSS 5.5
CVE-2014-3471 [MEDIUM] CVE-2014-3471 Qemu: hw: pci: use after free triggered via guest [fedora-all]
CVE-2014-3471 Qemu: hw: pci: use after free triggered via guest [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
NOTE: this issue affects multiple s
Bugzilla
CVE-2014-3471 Qemu: hw: pci: use after free triggered via guest
bugzilla·2014-06-23·CVSS 5.5
CVE-2014-3471 [MEDIUM] CVE-2014-3471 Qemu: hw: pci: use after free triggered via guest
CVE-2014-3471 Qemu: hw: pci: use after free triggered via guest
Qemu PCIe bus support is vulnerable to a use-after-free flaw. It could occur
via guest, when it tries to hotplug/hotunplug devices on the guest.
A user able to add & delete Virtio block devices on a guest could use this
flaw to crash the Qemu instance resulting in DoS.
Upstream fix:
-> git.qemu.org/?p=qemu.git;a=commit;h=554f802da3f8b09b16b9a84ad5847b2eb0e9ad2b
Discussion:
Statement:
This issue does not affect the versions of kvm package as shipped with Red Hat
Enterprise Linux 5.
This issue does not affect the versions of qemu-kvm package as shipped with Red Hat Enterprise Linux 6.
This issue does not affect the versions of qemu-kvm package as shipped with Red Hat Enterprise Linux 7.
---
Created qemu tracking bugs f
http://security.gentoo.org/glsa/glsa-201412-01.xmlhttp://www.openwall.com/lists/oss-security/2014/06/23/4http://www.securityfocus.com/bid/68145https://bugzilla.redhat.com/show_bug.cgi?id=1112271https://lists.gnu.org/archive/html/qemu-devel/2014-06/msg05283.htmlhttp://security.gentoo.org/glsa/glsa-201412-01.xmlhttp://www.openwall.com/lists/oss-security/2014/06/23/4http://www.securityfocus.com/bid/68145https://bugzilla.redhat.com/show_bug.cgi?id=1112271https://lists.gnu.org/archive/html/qemu-devel/2014-06/msg05283.html
2018-01-12
Published