CVE-2014-5263
published 2014-08-26CVE-2014-5263: vmstate_xhci_event in hw/usb/hcd-xhci.c in QEMU 1.6.0 does not terminate the list with the VMSTATE_END_OF_LIST macro, which allows attackers to cause a denial…
PriorityP429medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
1.57%
72.8th percentile
vmstate_xhci_event in hw/usb/hcd-xhci.c in QEMU 1.6.0 does not terminate the list with the VMSTATE_END_OF_LIST macro, which allows attackers to cause a denial of service (out-of-bounds access, infinite loop, and memory corruption) and possibly gain privileges via unspecified vectors.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | qemu | < qemu 2.1+dfsg-1 (bookworm) | qemu 2.1+dfsg-1 (bookworm) |
| qemu | qemu | — | — |
| qemu | qemu | >= 0 < 2.1+dfsg-1 | 2.1+dfsg-1 |
| qemu | qemu | >= 0 < 2.1+dfsg-1 | 2.1+dfsg-1 |
| qemu | qemu | >= 0 < 2.1+dfsg-1 | 2.1+dfsg-1 |
| qemu | qemu | >= 0 < 2.1+dfsg-1 | 2.1+dfsg-1 |
| qemu | qemu | >= 0 < 2.0.0+dfsg-2ubuntu1.7 | 2.0.0+dfsg-2ubuntu1.7 |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
vendor_ubuntu2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
QEMU vulnerabilities
vendor_ubuntu·2014-11-13·CVSS 2.1
CVE-2014-3615 [LOW] QEMU vulnerabilities
Title: QEMU vulnerabilities
Summary: Several security issues were fixed in QEMU.
Laszlo Ersek discovered that QEMU incorrectly handled memory in the vga
device. A malicious guest could possibly use this issue to read arbitrary
host memory. This issue only affected Ubuntu 14.04 LTS and Ubuntu 14.10.
(CVE-2014-3615)
Xavier Mehrenberger and Stephane Duverger discovered that QEMU incorrectly
handled certain udp packets when using guest networking. A malicious guest
could possibly use this issue to cause a denial of service. (CVE-2014-3640)
It was discovered that QEMU incorrectly handled parameter validation in
the vmware_vga device. A malicious guest could possibly use this issue to
write into memory of the host, leading to privilege escalation.
(CVE-2014-3689)
It was discovered that QEMU
Red Hat
qemu: missing field list terminator in vmstate_xhci_event
vendor_redhat·2014-07-22·CVSS 6.8
CVE-2014-5263 [MEDIUM] qemu: missing field list terminator in vmstate_xhci_event
qemu: missing field list terminator in vmstate_xhci_event
vmstate_xhci_event in hw/usb/hcd-xhci.c in QEMU 1.6.0 does not terminate the list with the VMSTATE_END_OF_LIST macro, which allows attackers to cause a denial of service (out-of-bounds access, infinite loop, and memory corruption) and possibly gain privileges via unspecified vectors.
Statement: Not vulnerable.
This issue does not affect the versions of kvm package as shipped with
Red Hat Enterprise Linux 5 and versions of qemu-kvm package as shipped with
Red Hat Enterprise Linux 6 because they did not backport the commit that
introduced this issue.
This issue does not affect the versions of qemu-kvm package as shipped with
Red Hat Enterprise Linux 7 because the layout of qemu-kvm binary does not
allow successful exploitation of th
Debian
CVE-2014-5263: qemu - vmstate_xhci_event in hw/usb/hcd-xhci.c in QEMU 1.6.0 does not terminate the lis...
vendor_debian·2014·CVSS 6.8
CVE-2014-5263 [MEDIUM] CVE-2014-5263: qemu - vmstate_xhci_event in hw/usb/hcd-xhci.c in QEMU 1.6.0 does not terminate the lis...
vmstate_xhci_event in hw/usb/hcd-xhci.c in QEMU 1.6.0 does not terminate the list with the VMSTATE_END_OF_LIST macro, which allows attackers to cause a denial of service (out-of-bounds access, infinite loop, and memory corruption) and possibly gain privileges via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 2.1+dfsg-1)
bullseye: resolved (fixed in 2.1+dfsg-1)
forky: resolved (fixed in 2.1+dfsg-1)
sid: resolved (fixed in 2.1+dfsg-1)
trixie: resolved (fixed in 2.1+dfsg-1)
GHSA
GHSA-qxm2-g26p-5vjg: vmstate_xhci_event in hw/usb/hcd-xhci
ghsa_unreviewed·2022-05-17
CVE-2014-5263 [MEDIUM] CWE-119 GHSA-qxm2-g26p-5vjg: vmstate_xhci_event in hw/usb/hcd-xhci
vmstate_xhci_event in hw/usb/hcd-xhci.c in QEMU 1.6.0 does not terminate the list with the VMSTATE_END_OF_LIST macro, which allows attackers to cause a denial of service (out-of-bounds access, infinite loop, and memory corruption) and possibly gain privileges via unspecified vectors.
OSV
qemu, qemu-kvm vulnerabilities
osv·2014-11-13·CVSS 2.1
CVE-2014-3615 [LOW] qemu, qemu-kvm vulnerabilities
qemu, qemu-kvm vulnerabilities
Laszlo Ersek discovered that QEMU incorrectly handled memory in the vga
device. A malicious guest could possibly use this issue to read arbitrary
host memory. This issue only affected Ubuntu 14.04 LTS and Ubuntu 14.10.
(CVE-2014-3615)
Xavier Mehrenberger and Stephane Duverger discovered that QEMU incorrectly
handled certain udp packets when using guest networking. A malicious guest
could possibly use this issue to cause a denial of service. (CVE-2014-3640)
It was discovered that QEMU incorrectly handled parameter validation in
the vmware_vga device. A malicious guest could possibly use this issue to
write into memory of the host, leading to privilege escalation.
(CVE-2014-3689)
It was discovered that QEMU incorrectly handled USB xHCI controller live
migra
OSV
CVE-2014-5263: vmstate_xhci_event in hw/usb/hcd-xhci
osv·2014-08-26·CVSS 6.8
CVE-2014-5263 [MEDIUM] CVE-2014-5263: vmstate_xhci_event in hw/usb/hcd-xhci
vmstate_xhci_event in hw/usb/hcd-xhci.c in QEMU 1.6.0 does not terminate the list with the VMSTATE_END_OF_LIST macro, which allows attackers to cause a denial of service (out-of-bounds access, infinite loop, and memory corruption) and possibly gain privileges via unspecified vectors.
No detection rules found.
No public exploits indexed.
http://git.qemu.org/?p=qemu.git%3Ba=commitdiff%3Bh=3afca1d6d413592c2b78cf28f52fa24a586d8f56http://www.openwall.com/lists/oss-security/2014/08/04/1http://www.openwall.com/lists/oss-security/2014/08/16/1http://www.ubuntu.com/usn/USN-2409-1https://bugzilla.redhat.com/show_bug.cgi?id=1126543http://git.qemu.org/?p=qemu.git%3Ba=commitdiff%3Bh=3afca1d6d413592c2b78cf28f52fa24a586d8f56http://www.openwall.com/lists/oss-security/2014/08/04/1http://www.openwall.com/lists/oss-security/2014/08/16/1http://www.ubuntu.com/usn/USN-2409-1https://bugzilla.redhat.com/show_bug.cgi?id=1126543
2014-08-26
Published