REDHAT-BUG-2278875: High severity Qemu qemu-img vulnerability
A flaw was found in the QEMU disk image utility (qemu-img) 'info' command. A specially crafted image file containing a json:{} value describing block devices in QMP could cause the qemu-img process on the host to consume large amounts of memory or CPU time, leading to denial of service, or read/write to an existing external file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2278875?
The severity of REDHAT-BUG-2278875 is classified as a denial of service vulnerability due to resource exhaustion.
How do I fix REDHAT-BUG-2278875?
To fix REDHAT-BUG-2278875, upgrade to the latest version of QEMU containing the necessary patches.
What software is affected by REDHAT-BUG-2278875?
REDHAT-BUG-2278875 affects the QEMU disk image utility known as qemu-img.
What type of attack does REDHAT-BUG-2278875 enable?
REDHAT-BUG-2278875 enables denial of service attacks by causing excessive memory or CPU consumption.
What command in QEMU is related to REDHAT-BUG-2278875?
The command related to REDHAT-BUG-2278875 is the 'info' command in the qemu-img utility.