CVE-2014-0222
Qemu: qcow1: validate L2 table size to avoid integer overflows
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Integer overflow in the qcow_open function in block/qcow.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service (crash) via a large L2 table in a QCOW version 1 image.
Desbordamiento de enteros en la función qcow_open en block/qcow.c en QEMU anterior a 1.7.2 permite a atacantes remotos causara una denegación de servicio (caída) a través de una tabla L2 grande en un imagen QCOW versión 1.
An integer overflow flaw was found in the QEMU block driver for QCOW version 1 disk images. A user able to alter the QEMU disk image files loaded by a guest could use this flaw to corrupt QEMU process memory on the host, which could potentially result in arbitrary code execution on the host with the privileges of the QEMU process.
The rhev-hypervisor6 package provides a Red Hat Enterprise Virtualization Hypervisor ISO disk image. The Red Hat Enterprise Virtualization Hypervisor is a dedicated Kernel-based Virtual Machine hypervisor. It includes everything necessary to run and manage virtual machines: a subset of the Red Hat Enterprise Linux operating environment and the Red Hat Enterprise Virtualization Agent. Note: Red Hat Enterprise Virtualization Hypervisor is only available for the Intel 64 and AMD64 architectures with virtualization extensions. A NULL pointer dereference flaw was found in the way the Linux kernel's networking implementation handled logging while processing certain invalid packets coming in via a VxLAN interface. A remote attacker could use this flaw to crash the system by sending a specially crafted packet to such an interface.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2013-12-03 CVE Reserved
- 2014-07-23 CVE Published
- 2024-08-06 CVE Updated
- 2024-08-06 First Exploit
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
- CWE-189: Numeric Errors
CAPEC
References (10)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/67357 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://lists.gnu.org/archive/html/qemu-devel/2014-05/msg02155.html | 2024-08-06 |
URL | Date | SRC |
---|---|---|
http://lists.nongnu.org/archive/html/qemu-stable/2014-07/msg00187.html | 2023-02-13 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Suse Search vendor "Suse" | Linux Enterprise Server Search vendor "Suse" for product "Linux Enterprise Server" | 11.0 Search vendor "Suse" for product "Linux Enterprise Server" and version "11.0" | sp1 |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | <= 1.7.1 Search vendor "Qemu" for product "Qemu" and version " <= 1.7.1" | - |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 0.1.0 Search vendor "Qemu" for product "Qemu" and version "0.1.0" | - |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 0.1.1 Search vendor "Qemu" for product "Qemu" and version "0.1.1" | - |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 0.1.2 Search vendor "Qemu" for product "Qemu" and version "0.1.2" | - |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 0.1.3 Search vendor "Qemu" for product "Qemu" and version "0.1.3" | - |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 0.1.4 Search vendor "Qemu" for product "Qemu" and version "0.1.4" | - |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 0.1.5 Search vendor "Qemu" for product "Qemu" and version "0.1.5" | - |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 0.1.6 Search vendor "Qemu" for product "Qemu" and version "0.1.6" | - |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 0.2.0 Search vendor "Qemu" for product "Qemu" and version "0.2.0" | - |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 0.3.0 Search vendor "Qemu" for product "Qemu" and version "0.3.0" | - |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 0.4.0 Search vendor "Qemu" for product "Qemu" and version "0.4.0" | - |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 0.4.1 Search vendor "Qemu" for product "Qemu" and version "0.4.1" | - |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 0.4.2 Search vendor "Qemu" for product "Qemu" and version "0.4.2" | - |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 0.4.3 Search vendor "Qemu" for product "Qemu" and version "0.4.3" | - |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 0.5.0 Search vendor "Qemu" for product "Qemu" and version "0.5.0" | - |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 0.5.1 Search vendor "Qemu" for product "Qemu" and version "0.5.1" | - |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 0.5.2 Search vendor "Qemu" for product "Qemu" and version "0.5.2" | - |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 0.5.3 Search vendor "Qemu" for product "Qemu" and version "0.5.3" | - |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 0.5.4 Search vendor "Qemu" for product "Qemu" and version "0.5.4" | - |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 0.5.5 Search vendor "Qemu" for product "Qemu" and version "0.5.5" | - |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 0.6.0 Search vendor "Qemu" for product "Qemu" and version "0.6.0" | - |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 0.6.1 Search vendor "Qemu" for product "Qemu" and version "0.6.1" | - |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 0.7.0 Search vendor "Qemu" for product "Qemu" and version "0.7.0" | - |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 0.7.1 Search vendor "Qemu" for product "Qemu" and version "0.7.1" | - |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 0.7.2 Search vendor "Qemu" for product "Qemu" and version "0.7.2" | - |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 0.8.0 Search vendor "Qemu" for product "Qemu" and version "0.8.0" | - |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 0.8.1 Search vendor "Qemu" for product "Qemu" and version "0.8.1" | - |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 0.8.2 Search vendor "Qemu" for product "Qemu" and version "0.8.2" | - |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 0.9.0 Search vendor "Qemu" for product "Qemu" and version "0.9.0" | - |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 0.9.1 Search vendor "Qemu" for product "Qemu" and version "0.9.1" | - |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 0.9.1-5 Search vendor "Qemu" for product "Qemu" and version "0.9.1-5" | - |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 0.10.0 Search vendor "Qemu" for product "Qemu" and version "0.10.0" | - |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 0.10.1 Search vendor "Qemu" for product "Qemu" and version "0.10.1" | - |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 0.10.2 Search vendor "Qemu" for product "Qemu" and version "0.10.2" | - |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 0.10.3 Search vendor "Qemu" for product "Qemu" and version "0.10.3" | - |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 0.10.4 Search vendor "Qemu" for product "Qemu" and version "0.10.4" | - |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 0.10.5 Search vendor "Qemu" for product "Qemu" and version "0.10.5" | - |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 0.10.6 Search vendor "Qemu" for product "Qemu" and version "0.10.6" | - |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 0.11.0 Search vendor "Qemu" for product "Qemu" and version "0.11.0" | - |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 0.11.0 Search vendor "Qemu" for product "Qemu" and version "0.11.0" | rc0 |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 0.11.0 Search vendor "Qemu" for product "Qemu" and version "0.11.0" | rc1 |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 0.11.0 Search vendor "Qemu" for product "Qemu" and version "0.11.0" | rc2 |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 0.11.0-rc0 Search vendor "Qemu" for product "Qemu" and version "0.11.0-rc0" | - |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 0.11.0-rc1 Search vendor "Qemu" for product "Qemu" and version "0.11.0-rc1" | - |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 0.11.0-rc2 Search vendor "Qemu" for product "Qemu" and version "0.11.0-rc2" | - |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 0.11.1 Search vendor "Qemu" for product "Qemu" and version "0.11.1" | - |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 0.12.0 Search vendor "Qemu" for product "Qemu" and version "0.12.0" | - |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 0.12.0 Search vendor "Qemu" for product "Qemu" and version "0.12.0" | rc1 |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 0.12.0 Search vendor "Qemu" for product "Qemu" and version "0.12.0" | rc2 |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 0.12.1 Search vendor "Qemu" for product "Qemu" and version "0.12.1" | - |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 0.12.2 Search vendor "Qemu" for product "Qemu" and version "0.12.2" | - |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 0.12.3 Search vendor "Qemu" for product "Qemu" and version "0.12.3" | - |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 0.12.4 Search vendor "Qemu" for product "Qemu" and version "0.12.4" | - |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 0.12.5 Search vendor "Qemu" for product "Qemu" and version "0.12.5" | - |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 0.13.0 Search vendor "Qemu" for product "Qemu" and version "0.13.0" | - |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 0.13.0 Search vendor "Qemu" for product "Qemu" and version "0.13.0" | rc0 |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 0.13.0 Search vendor "Qemu" for product "Qemu" and version "0.13.0" | rc1 |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 0.14.0 Search vendor "Qemu" for product "Qemu" and version "0.14.0" | - |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 0.14.0 Search vendor "Qemu" for product "Qemu" and version "0.14.0" | rc0 |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 0.14.0 Search vendor "Qemu" for product "Qemu" and version "0.14.0" | rc1 |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 0.14.0 Search vendor "Qemu" for product "Qemu" and version "0.14.0" | rc2 |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 0.14.1 Search vendor "Qemu" for product "Qemu" and version "0.14.1" | - |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 0.15.0 Search vendor "Qemu" for product "Qemu" and version "0.15.0" | rc1 |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 0.15.0 Search vendor "Qemu" for product "Qemu" and version "0.15.0" | rc2 |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 0.15.1 Search vendor "Qemu" for product "Qemu" and version "0.15.1" | - |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 0.15.2 Search vendor "Qemu" for product "Qemu" and version "0.15.2" | - |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 1.0 Search vendor "Qemu" for product "Qemu" and version "1.0" | - |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 1.0 Search vendor "Qemu" for product "Qemu" and version "1.0" | rc1 |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 1.0 Search vendor "Qemu" for product "Qemu" and version "1.0" | rc2 |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 1.0 Search vendor "Qemu" for product "Qemu" and version "1.0" | rc3 |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 1.0 Search vendor "Qemu" for product "Qemu" and version "1.0" | rc4 |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 1.0.1 Search vendor "Qemu" for product "Qemu" and version "1.0.1" | - |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 1.1 Search vendor "Qemu" for product "Qemu" and version "1.1" | - |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 1.1 Search vendor "Qemu" for product "Qemu" and version "1.1" | rc1 |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 1.1 Search vendor "Qemu" for product "Qemu" and version "1.1" | rc2 |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 1.1 Search vendor "Qemu" for product "Qemu" and version "1.1" | rc3 |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 1.1 Search vendor "Qemu" for product "Qemu" and version "1.1" | rc4 |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 1.4.1 Search vendor "Qemu" for product "Qemu" and version "1.4.1" | - |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 1.4.2 Search vendor "Qemu" for product "Qemu" and version "1.4.2" | - |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 1.5.0 Search vendor "Qemu" for product "Qemu" and version "1.5.0" | - |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 1.5.0 Search vendor "Qemu" for product "Qemu" and version "1.5.0" | rc1 |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 1.5.0 Search vendor "Qemu" for product "Qemu" and version "1.5.0" | rc2 |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 1.5.0 Search vendor "Qemu" for product "Qemu" and version "1.5.0" | rc3 |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 1.5.1 Search vendor "Qemu" for product "Qemu" and version "1.5.1" | - |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 1.5.2 Search vendor "Qemu" for product "Qemu" and version "1.5.2" | - |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 1.5.3 Search vendor "Qemu" for product "Qemu" and version "1.5.3" | - |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 1.6.0 Search vendor "Qemu" for product "Qemu" and version "1.6.0" | - |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 1.6.0 Search vendor "Qemu" for product "Qemu" and version "1.6.0" | rc1 |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 1.6.0 Search vendor "Qemu" for product "Qemu" and version "1.6.0" | rc2 |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 1.6.0 Search vendor "Qemu" for product "Qemu" and version "1.6.0" | rc3 |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 1.6.1 Search vendor "Qemu" for product "Qemu" and version "1.6.1" | - |
Affected
| ||||||
Qemu Search vendor "Qemu" | Qemu Search vendor "Qemu" for product "Qemu" | 1.6.2 Search vendor "Qemu" for product "Qemu" and version "1.6.2" | - |
Affected
|