Back

HIGH

QEMU: out of bounds buffer accesses, guest triggerable via IDE SMART

Published Apr 23, 2014

Description

Off-by-one error in the cmd_smart function in the smart self test in hw/ide/core.c in QEMU before 2.0 allows local users to have unspecified impact via a SMART EXECUTE OFFLINE command that triggers a buffer underflow and memory corruption.

Affected products

Remediation

Red Hat statement

This issue does not affect the versions of kvm package as shipped with Red Hat Enterprise Linux 5.

References (16)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Apr 23, 2014
Updated Aug 6, 2024
Reserved Apr 17, 2014
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Apr 14, 2014