CVE-2024-4467
Qemu-kvm: 'qemu-img info' leads to host file read/write
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A flaw was found in the QEMU disk image utility (qemu-img) 'info' command. A specially crafted image file containing a `json:{}` value describing block devices in QMP could cause the qemu-img process on the host to consume large amounts of memory or CPU time, leading to denial of service or read/write to an existing external file.
Se encontró una falla en el comando 'info' de la utilidad de imagen de disco QEMU (qemu-img). Un archivo de imagen especialmente manipulado que contenga un valor `json:{}` que describa los dispositivos de bloque en QMP podría provocar que el proceso qemu-img en el host consuma grandes cantidades de memoria o tiempo de CPU, lo que provocaría una denegación de servicio o lectura/escritura en un archivo externo existente.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2024-05-03 CVE Reserved
- 2024-07-02 CVE Published
- 2024-09-13 CVE Updated
- 2024-09-14 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-400: Uncontrolled Resource Consumption
CAPEC
References (12)
URL | Tag | Source |
---|---|---|
http://www.openwall.com/lists/oss-security/2024/07/23/2 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://access.redhat.com/errata/RHSA-2024:4276 | 2024-07-23 | |
https://access.redhat.com/errata/RHSA-2024:4277 | 2024-07-23 | |
https://access.redhat.com/errata/RHSA-2024:4278 | 2024-07-23 | |
https://access.redhat.com/errata/RHSA-2024:4372 | 2024-07-23 | |
https://access.redhat.com/errata/RHSA-2024:4373 | 2024-07-23 | |
https://access.redhat.com/errata/RHSA-2024:4374 | 2024-07-23 | |
https://access.redhat.com/errata/RHSA-2024:4420 | 2024-07-23 | |
https://access.redhat.com/errata/RHSA-2024:4724 | 2024-07-23 | |
https://access.redhat.com/errata/RHSA-2024:4727 | 2024-07-23 | |
https://access.redhat.com/security/cve/CVE-2024-4467 | 2024-07-23 | |
https://bugzilla.redhat.com/show_bug.cgi?id=2278875 | 2024-07-23 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
- | - | - | - | - |