The (1) BMDMA and (2) AHCI HBA interfaces in the IDE functionality in QEMU 1.0 through 2.1.3 have multiple interpretations of a function's return value, which allows guest OS users to cause a host OS denial of service (memory consumption or infinite loop, and system crash) via a PRDT with zero complete sectors, related to the bmdma_prepare_buf and ahci_dma_prepare_buf functions.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade qemu | Aug 30, 2017 | Apr 21, 2015 |
| Debian | — | Upgrade qemu | Jul 30, 2024 | Apr 21, 2015 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Oct 31, 2014 |
| Suse | — | Upgrade qemu-toolsUpgrade qemu-ipxeUpgrade qemu-block-rbdUpgrade xen-develUpgrade xen-kmp-paeUpgrade xen-toolsUpgrade qemu-guest-agentUpgrade qemu-seabiosUpgrade qemu-block-curlUpgrade qemu-ppcUpgrade qemu-langUpgrade qemuUpgrade qemu-kvmUpgrade xen-doc-htmlUpgrade qemu-sgabiosUpgrade xen-doc-pdfUpgrade kvmUpgrade qemu-x86Upgrade xen-libs-32bitUpgrade xen-kmp-defaultUpgrade qemu-vgabiosUpgrade xenUpgrade xen-libsUpgrade xen-tools-domUUpgrade qemu-s390 | Mar 28, 2016 | Apr 21, 2015 |
| Ubuntu | — | Upgrade qemu-system-ppcUpgrade qemu-system-mipsUpgrade qemu-system-x86Upgrade qemu-systemUpgrade qemu-system-sparcUpgrade qemu-kvmUpgrade qemu-system-armUpgrade qemu-system-miscUpgrade qemu-system-aarch64 | Nov 8, 2024 | Apr 21, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub