Off-by-one error in the pci_read function in the ACPI PCI hotplug interface (hw/acpi/pcihp.c) in QEMU allows local guest users to obtain sensitive information and have other unspecified impact related to a crafted PCI device that triggers memory corruption.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade qemu | Jul 30, 2024 | Nov 15, 2014 |
| Gentoo Linux | — | Upgrade app-emulation/qemu. | Oct 30, 2017 | Nov 15, 2014 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Aug 19, 2014 |
| Suse | — | Upgrade qemu-s390Upgrade qemu-block-rbdUpgrade qemu-vgabiosUpgrade qemu-seabiosUpgrade qemu-kvmUpgrade qemu-block-curlUpgrade qemu-ipxeUpgrade qemu-sgabiosUpgrade qemu-ppcUpgrade qemuUpgrade qemu-toolsUpgrade qemu-langUpgrade qemu-x86Upgrade qemu-guest-agent | Nov 13, 2016 | Nov 15, 2014 |
| Ubuntu | — | Upgrade qemu-kvmUpgrade qemu-system-x86Upgrade qemu-system-armUpgrade qemu-systemUpgrade qemu-system-aarch64Upgrade qemu-system-sparcUpgrade qemu-system-ppcUpgrade qemu-system-miscUpgrade qemu-system-mips | Nov 8, 2024 | Nov 15, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub