CVE-2014-0147: Integer Overflow
Qemu before 1.6.2 block diver for the various disk image formats used by Bochs and for the QCOW version 2 format, are vulnerable to a possible crash caused by signed data types or a logic error while creating QCOW2 snapshots, which leads to incorrectly calling updaterefcount() routine.
Other sources
Qemu block diver for the various disk image formats used by Bochs and for the QCOW version 2 format, are vulnerable to a possible crash caused by signed data types or a logic error while creating QCOW2 snapshots, which leads to incorrectly calling updaterefcount() routine.
An user able to alter the Qemu disk image files loaded by a guest could use this flaw to crash the Qemu instance resulting in DoS or corrupt QEMU process memory on the host, which could potentially result in arbitrary code execution on the host with the privileges of the QEMU process.
Upstream fix: ------------- qcow2: Don't rely on freeclusterindex in allocrefcountbl -> http://git.qemu.org/?p=qemu.git;a=commit;h=b106ad9185f35fc4ad669555ad0e79e276083bd7
bochs: Use unsigned variables for offsets and sizes -> http://git.qemu.org/?p=qemu.git;a=commit;h=246f65838d19db6db55bfb41117c35645a2c4789
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2014-0147?
CVE-2014-0147 is a vulnerability in Qemu which allows for a possible crash caused by signed data types or a logic error while creating QCOW2 snapshots.
What software is affected by CVE-2014-0147?
Qemu versions before 1.6.2, Fedoraproject Fedora 20, Redhat Virtualization 3.0, Redhat Enterprise Linux Desktop 6.0, Redhat Enterprise Linux Eus 6.5, Redhat Enterprise Linux Openstack Platform 5, Redhat Enterprise Linux Server 6.0, Redhat Enterprise Linux Server Aus 6.5, and Redhat Enterprise Linux Server Tus 6.5 are affected by CVE-2014-0147.
What is the severity of CVE-2014-0147?
CVE-2014-0147 has a severity level of medium with a CVSS score of 6.2.
How can I fix CVE-2014-0147?
Update your Qemu software to version 1.6.2 or later to fix CVE-2014-0147.
Where can I find more information about CVE-2014-0147?
You can find more information about CVE-2014-0147 at the following links: [link1], [link2], [link3].