CVE-2014-9718: Medium severity Debian Debian Linux vulnerability
The (1) BMDMA and (2) AHCI HBA interfaces in the IDE functionality in QEMU 1.0 through 2.1.3 have multiple interpretations of a function's return value, which allows guest OS users to cause a host OS denial of service (memory consumption or infinite loop, and system crash) via a PRDT with zero complete sectors, related to the bmdmapreparebuf and ahcidmapreparebuf functions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9718?
CVE-2014-9718 has been classified as high severity due to its potential to cause denial of service on host systems.
How do I fix CVE-2014-9718?
To fix CVE-2014-9718, upgrade to a patched version of QEMU, specifically versions after 2.1.3.
What versions of QEMU are affected by CVE-2014-9718?
CVE-2014-9718 affects QEMU versions from 1.0 through 2.1.3.
How does CVE-2014-9718 affect QEMU users?
CVE-2014-9718 allows guest OS users to exploit weaknesses that lead to memory consumption or infinite loops on the host.
Is CVE-2014-9718 specific to any operating system?
CVE-2014-9718 is not limited to a specific operating system; it affects any host running the vulnerable versions of QEMU.