CVE-2014-9718: Medium severity Debian Debian Linux vulnerability

Published Apr 21, 2015
·
Updated

The (1) BMDMA and (2) AHCI HBA interfaces in the IDE functionality in QEMU 1.0 through 2.1.3 have multiple interpretations of a function's return value, which allows guest OS users to cause a host OS denial of service (memory consumption or infinite loop, and system crash) via a PRDT with zero complete sectors, related to the bmdmapreparebuf and ahcidmapreparebuf functions.

Affected Software

43 affected components
Debian Debian Linux=8.0
Qemu Qemu=1.0
Qemu Qemu=1.0-rc1
Qemu Qemu=1.0-rc2
Qemu Qemu=1.0-rc3
Qemu Qemu=1.0-rc4
Qemu Qemu=1.0.1
Qemu Qemu=1.1
Qemu Qemu=1.1-rc1
Qemu Qemu=1.1-rc2
Qemu Qemu=1.1-rc3
Qemu Qemu=1.1-rc4
Qemu Qemu=1.4.1
Qemu Qemu=1.4.2
Qemu Qemu=1.5.0
Qemu Qemu=1.5.0-rc1
Qemu Qemu=1.5.0-rc2
Qemu Qemu=1.5.0-rc3
Qemu Qemu=1.5.1
Qemu Qemu=1.5.2
Qemu Qemu=1.5.3
Qemu Qemu=1.6.0
Qemu Qemu=1.6.0-rc1
Qemu Qemu=1.6.0-rc2
Qemu Qemu=1.6.0-rc3
Qemu Qemu=1.6.1
Qemu Qemu=1.6.2
Qemu Qemu=1.7.1
Qemu Qemu=2.0.0
Qemu Qemu=2.0.0-rc0
Qemu Qemu=2.0.0-rc1
Qemu Qemu=2.0.0-rc2
Qemu Qemu=2.0.0-rc3
Qemu Qemu=2.0.2
Qemu Qemu=2.1.0
Qemu Qemu=2.1.0-rc0
Qemu Qemu=2.1.0-rc1
Qemu Qemu=2.1.0-rc2
Qemu Qemu=2.1.0-rc3
Qemu Qemu=2.1.0-rc5
Qemu Qemu=2.1.1
Qemu Qemu=2.1.2
Qemu Qemu=2.1.3

Event History

Apr 21, 2015
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description

Frequently Asked Questions

1

What is the severity of CVE-2014-9718?

CVE-2014-9718 has been classified as high severity due to its potential to cause denial of service on host systems.

2

How do I fix CVE-2014-9718?

To fix CVE-2014-9718, upgrade to a patched version of QEMU, specifically versions after 2.1.3.

3

What versions of QEMU are affected by CVE-2014-9718?

CVE-2014-9718 affects QEMU versions from 1.0 through 2.1.3.

4

How does CVE-2014-9718 affect QEMU users?

CVE-2014-9718 allows guest OS users to exploit weaknesses that lead to memory consumption or infinite loops on the host.

5

Is CVE-2014-9718 specific to any operating system?

CVE-2014-9718 is not limited to a specific operating system; it affects any host running the vulnerable versions of QEMU.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203