QEMU before 2.0.0 block drivers for CLOOP, QCOW2 version 2 and various other image formats are vulnerable to potential memory corruptions, integer/buffer overflows or crash caused by missing input validations which could allow a remote user to execute arbitrary code on the host with the privileges of the QEMU process.
CVSS Details
- CVSS 3.1 Base Score: 8.6
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade qemu-kvmUpgrade qemu-guest-agentUpgrade qemu-imgUpgrade qemu-kvm-tools | Aug 17, 2018 | Apr 22, 2014 |
| Debian | — | Upgrade qemuUpgrade qemu-kvm | Jul 30, 2024 | Sep 29, 2022 |
| Gentoo Linux | — | Upgrade app-emulation/qemu. | Oct 30, 2017 | Aug 30, 2014 |
| Oracle_linux | — | Upgrade qemu-imgUpgrade qemu-kvm-toolsUpgrade qemu-guest-agentUpgrade qemu-kvm | Oct 16, 2024 | Feb 11, 2020 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Sep 29, 2022 |
| Suse | — | Upgrade qemu-x86Upgrade qemuUpgrade kvmUpgrade qemu-kvmUpgrade qemu-sgabiosUpgrade qemu-ppcUpgrade qemu-armUpgrade qemu-toolsUpgrade qemu-guest-agentUpgrade qemu-vgabiosUpgrade qemu-block-rbdUpgrade qemu-s390Upgrade qemu-seabiosUpgrade qemu-block-sshUpgrade qemu-block-curlUpgrade qemu-block-iscsiUpgrade qemu-ksmUpgrade qemu-ipxeUpgrade qemu-lang | Dec 18, 2015 | May 8, 2014 |
| Ubuntu | — | Upgrade qemu-systemUpgrade qemu-system-aarch64Upgrade qemu-system-miscUpgrade qemu-system-x86Upgrade qemu-system-sparcUpgrade qemu-system-mipsUpgrade qemu-kvmUpgrade qemu-system-ppcUpgrade qemu-system-arm | Nov 8, 2024 | Sep 29, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub