Qemu: block: multiple integer overflow flaws
Published Aug 10, 2017
7.0
HIGHCVSS 3.0
EPSS 0.40%
Description
Multiple integer overflows in the block drivers in QEMU, possibly before 2.0.0, allow local users to cause a denial of service (crash) via a crafted catalog size in (1) the parallels_open function in block/parallels.c or (2) bochs_open function in bochs.c, a large L1 table in the (3) qcow2_snapshot_load_tmp in qcow2-snapshot.c or (4) qcow2_grow_l1_table function in qcow2-cluster.c, (5) a large request in the bdrv_check_byte_request function in block.c and other block drivers, (6) crafted cluster indexes in the get_refcount function in qcow2-refcount.c, or (7) a large number of blocks in the cloop_open function in cloop.c, which trigger buffer overflows, memory corruption, large memory allocations and out-of-bounds read and writes.
Affected products
No data.
Configuration 1
- 6.0
No data.
OpenStack 3 for RHEL 6
qemu-kvm-rhev-2:0.12.1.2-2.415.el6_5.8
Fixed · RHSA-2014:0435
OpenStack 4 for RHEL 6
qemu-kvm-rhev-2:0.12.1.2-2.415.el6_5.8
Fixed · RHSA-2014:0434
RHEV 3.X Hypervisor and Agents for RHEL-6
qemu-kvm-rhev-2:0.12.1.2-2.415.el6_5.8
Fixed · RHSA-2014:0421
RHEV 3.X Hypervisor and Agents for RHEL-6
rhev-hypervisor6-0:6.5-20140603.2.el6ev
Fixed · RHSA-2014:0674
Red Hat Enterprise Linux 6
qemu-kvm-2:0.12.1.2-2.415.el6_5.8
Fixed · RHSA-2014:0420
Red Hat Enterprise Linux 5
kvm
Will not fix
Red Hat Enterprise Linux 7
qemu-kvm
Not affected
Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse)
qemu-kvm-rhev
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| OpenStack 3 for RHEL 6 | qemu-kvm-rhev-2:0.12.1.2-2.415.el6_5.8 | Fixed | RHSA-2014:0435 |
| OpenStack 4 for RHEL 6 | qemu-kvm-rhev-2:0.12.1.2-2.415.el6_5.8 | Fixed | RHSA-2014:0434 |
| RHEV 3.X Hypervisor and Agents for RHEL-6 | qemu-kvm-rhev-2:0.12.1.2-2.415.el6_5.8 | Fixed | RHSA-2014:0421 |
| RHEV 3.X Hypervisor and Agents for RHEL-6 | rhev-hypervisor6-0:6.5-20140603.2.el6ev | Fixed | RHSA-2014:0674 |
| Red Hat Enterprise Linux 6 | qemu-kvm-2:0.12.1.2-2.415.el6_5.8 | Fixed | RHSA-2014:0420 |
| Red Hat Enterprise Linux 5 | kvm | Will not fix | n/a |
| Red Hat Enterprise Linux 7 | qemu-kvm | Not affected | n/a |
| Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse) | qemu-kvm-rhev | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
AV:L/AC:M/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (10 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.40% (0.00402) | 32.08th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.40% (0.00402) | 31.77th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.09% (0.00089) | 23.34th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.04% (0.00042) | 5.09th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.04% (0.00042) | 5.67th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.28% (0.01282) | 68.34th | v2 (v2022.01.01) |
| Feb 13, 2023 | 1.28% (0.01282) | 67.79th | v2 (v2022.01.01) |
| Feb 3, 2023 | 1.55% (0.01547) | 74.40th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.28% (0.01282) | 65.91th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.28% (0.01282) | 41.72th | v2 (v2022.01.01) |
References (14)
- http://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=509a41bab5306181044b5fff02eadf96d9c8676a x_refsource_CONFIRM
- http://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=6a83f8b5bec6f59e56cc49bd49e4c3f8f805d56f x_refsource_CONFIRM
- http://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=8f4754ede56e3f9ea3fd7207f4a7c4453e59285b x_refsource_CONFIRM
- http://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=afbcc40bee4ef51731102d7d4b499ee12fc182e1 x_refsource_CONFIRM
- http://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=cab60de930684c33f67d4e32c7509b567f8c445b x_refsource_CONFIRM
- http://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=db8a31d11d6a60f48d6817530640d75aa72a9a2f x_refsource_CONFIRM
- http://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=e3737b820b45e54b059656dc3f914f895ac7a88b x_refsource_CONFIRM
- http://rhn.redhat.com/errata/RHSA-2014-0420.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2014-0421.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://www.debian.org/security/2014/dsa-3044 vendor-advisoryx_refsource_DEBIAN
- https://access.redhat.com/security/cve/CVE-2014-0143 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1079140 x_refsource_CONFIRMIssue TrackingPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2014-0143
- https://www.cve.org/CVERecord?id=CVE-2014-0143
Change history (0)
No recorded changes yet.