Back

MEDIUM

qemu: missing field list terminator in vmstate_xhci_event

Published Aug 26, 2014

Description

vmstate_xhci_event in hw/usb/hcd-xhci.c in QEMU 1.6.0 does not terminate the list with the VMSTATE_END_OF_LIST macro, which allows attackers to cause a denial of service (out-of-bounds access, infinite loop, and memory corruption) and possibly gain privileges via unspecified vectors.

Affected products

Remediation

Red Hat statement

Not vulnerable. This issue does not affect the versions of kvm package as shipped with Red Hat Enterprise Linux 5 and versions of qemu-kvm package as shipped with Red Hat Enterprise Linux 6 because they did not backport the commit that introduced this issue. This issue does not affect the versions of qemu-kvm package as shipped with Red Hat Enterprise Linux 7 because the layout of qemu-kvm binary does not allow successful exploitation of this flaw.

Metrics

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Aug 26, 2014
Updated Aug 6, 2024
Reserved Aug 15, 2014
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Jul 22, 2014