Off-by-one error in the cmd_smart function in the smart self test in hw/ide/core.c in QEMU before 2.0 allows local users to have unspecified impact via a SMART EXECUTE OFFLINE command that triggers a buffer underflow and memory corruption.
CVSS Details
- CVSS 3.1 Base Score: 8.4
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade qemu-kvmUpgrade qemu-imgUpgrade qemu-kvm-toolsUpgrade qemu-guest-agent | Dec 1, 2016 | Apr 23, 2014 |
| Debian | — | Upgrade qemuUpgrade qemu-kvm | Jul 30, 2024 | Apr 23, 2014 |
| Gentoo Linux | — | Upgrade app-emulation/qemu. | Oct 30, 2017 | Apr 23, 2014 |
| Oracle_linux | — | Upgrade qemu-imgUpgrade qemu-kvmUpgrade libcacardUpgrade libcacard-toolsUpgrade qemu-guest-agentUpgrade qemu-kvm-toolsUpgrade qemu-kvm-commonUpgrade libcacard-devel | Oct 16, 2024 | Apr 23, 2014 |
| Suse | — | Upgrade kvm | Dec 18, 2015 | Apr 23, 2014 |
| Ubuntu | — | Upgrade qemu-system-mipsUpgrade qemu-system-sparcUpgrade qemu-system-aarch64Upgrade qemu-system-miscUpgrade qemu-system-ppcUpgrade qemu-systemUpgrade qemu-system-x86Upgrade qemu-system-armUpgrade qemu-kvm | Nov 8, 2024 | Apr 23, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub