QEMU: out of bounds buffer accesses, guest triggerable via IDE SMART
Published Apr 23, 2014
7.2
HIGHCVSS 2.0
EPSS 0.39%
Description
Off-by-one error in the cmd_smart function in the smart self test in hw/ide/core.c in QEMU before 2.0 allows local users to have unspecified impact via a SMART EXECUTE OFFLINE command that triggers a buffer underflow and memory corruption.
Affected products
No data.
- ≤ 1.7.1
- 0.1.0
- 0.1.1
- 0.1.2
- 0.1.3
- 0.1.4
- 0.1.5
- 0.1.6
- 0.2.0
- 0.3.0
- 0.4.0
- 0.4.1
- 0.4.2
- 0.4.3
- 0.5.0
- 0.5.1
- 0.5.2
- 0.5.3
- 0.5.4
- 0.5.5
- 0.6.0
- 0.6.1
- 0.7.0
- 0.7.1
- 0.7.2
- 0.8.0
- 0.8.1
- 0.8.2
- 0.9.0
- 0.9.1
- 0.9.1-5
- 0.10.0
- 0.10.1
- 0.10.2
- 0.10.3
- 0.10.4
- 0.10.5
- 0.10.6
- 0.11.0
- 0.11.0
- 0.11.0
- 0.11.0
- 0.11.0-rc0
- 0.11.0-rc1
- 0.11.0-rc2
- 0.11.1
- 0.12.0
- 0.12.0
- 0.12.0
- 0.12.1
- 0.12.2
- 0.12.3
- 0.12.4
- 0.12.5
- 0.13.0
- 0.13.0
- 0.13.0
- 0.14.0
- 0.14.0
- 0.14.0
- 0.14.0
- 0.14.1
- 0.15.0
- 0.15.0
- 0.15.1
- 0.15.2
- 1.0
- 1.0
- 1.0
- 1.0
- 1.0
- 1.0.1
- 1.1
- 1.1
- 1.1
- 1.1
- 1.1
- 1.1.1
- 1.1.2
- 1.2.0
- 1.2.0
- 1.2.0
- 1.2.0
- 1.2.0
- 1.2.1
- 1.2.2
- 1.3.0
- 1.3.0
- 1.3.0
- 1.3.0
- 1.3.1
- 1.4.0
- 1.4.0
- 1.4.1
- 1.4.2
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.1
- 1.5.2
- 1.5.3
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.1
- 1.6.2
No data.
OpenStack 3 for RHEL 6
qemu-kvm-rhev-2:0.12.1.2-2.415.el6_5.10
Fixed · RHSA-2014:0888
OpenStack 4 for RHEL 6
qemu-kvm-rhev-2:0.12.1.2-2.415.el6_5.10
Fixed · RHSA-2014:0888
RHEV 3.X Hypervisor and Agents for RHEL-6
qemu-kvm-rhev-2:0.12.1.2-2.415.el6_5.10
Fixed · RHSA-2014:0744
RHEV 3.X Hypervisor and Agents for RHEL-6
rhev-hypervisor6-0:6.5-20140603.2.el6ev
Fixed · RHSA-2014:0674
Red Hat Enterprise Linux 6
qemu-kvm-2:0.12.1.2-2.415.el6_5.10
Fixed · RHSA-2014:0743
Red Hat Enterprise Linux 7
qemu-kvm-10:1.5.3-60.el7_0.2
Fixed · RHSA-2014:0704
Red Hat Enterprise Linux 5
kvm
Not affected
Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse)
qemu-kvm-rhev
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| OpenStack 3 for RHEL 6 | qemu-kvm-rhev-2:0.12.1.2-2.415.el6_5.10 | Fixed | RHSA-2014:0888 |
| OpenStack 4 for RHEL 6 | qemu-kvm-rhev-2:0.12.1.2-2.415.el6_5.10 | Fixed | RHSA-2014:0888 |
| RHEV 3.X Hypervisor and Agents for RHEL-6 | qemu-kvm-rhev-2:0.12.1.2-2.415.el6_5.10 | Fixed | RHSA-2014:0744 |
| RHEV 3.X Hypervisor and Agents for RHEL-6 | rhev-hypervisor6-0:6.5-20140603.2.el6ev | Fixed | RHSA-2014:0674 |
| Red Hat Enterprise Linux 6 | qemu-kvm-2:0.12.1.2-2.415.el6_5.10 | Fixed | RHSA-2014:0743 |
| Red Hat Enterprise Linux 7 | qemu-kvm-10:1.5.3-60.el7_0.2 | Fixed | RHSA-2014:0704 |
| Red Hat Enterprise Linux 5 | kvm | Not affected | n/a |
| Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse) | qemu-kvm-rhev | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue does not affect the versions of kvm package as shipped with Red Hat Enterprise Linux 5.
References (16)
- http://rhn.redhat.com/errata/RHSA-2014-0704.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2014-0743.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2014-0744.html vendor-advisoryx_refsource_REDHAT
- http://secunia.com/advisories/57945 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/58191 third-party-advisoryx_refsource_SECUNIA
- http://www.openwall.com/lists/oss-security/2014/04/15/4 mailing-listx_refsource_MLIST
- http://www.openwall.com/lists/oss-security/2014/04/18/5 mailing-listx_refsource_MLIST
- http://www.securityfocus.com/bid/66932 vdb-entryx_refsource_BID
- http://www.ubuntu.com/usn/USN-2182-1 vendor-advisoryx_refsource_UBUNTU
- https://access.redhat.com/security/cve/CVE-2014-2894 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1087971 Issue Tracking
- https://lists.nongnu.org/archive/html/qemu-devel/2014-04/msg02016.html mailing-listx_refsource_MLIST
- https://lists.nongnu.org/archive/html/qemu-devel/2014-04/msg02095.html mailing-listx_refsource_MLIST
- https://lists.nongnu.org/archive/html/qemu-devel/2014-04/msg02152.html mailing-listx_refsource_MLIST
- https://nvd.nist.gov/vuln/detail/CVE-2014-2894
- https://www.cve.org/CVERecord?id=CVE-2014-2894
Change history (0)
No recorded changes yet.