An integer overflow flaw was found in the QEMU block driver for QCOW version 1 disk images. A user able to alter the QEMU disk image files loaded by a guest could use this flaw to corrupt QEMU process memory on the host, which could potentially result in arbitrary code execution on the host with the privileges of the QEMU process.
Find out more about CVE-2014-0222 from the MITRE CVE dictionary dictionary and NIST NVD.
Base Score | 4.3 |
---|---|
Base Metrics | AV:A/AC:H/Au:N/C:P/I:P/A:P |
Access Vector | Adjacent Network |
Access Complexity | High |
Authentication | None |
Confidentiality Impact | Partial |
Integrity Impact | Partial |
Availability Impact | Partial |
Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).
Platform | Errata | Release Date |
---|---|---|
Red Hat Enterprise Linux OpenStack Platform 4.0 (qemu-kvm-rhev) | RHSA-2014:1187 | 2014-09-15 |
Red Hat Enterprise Linux 7 (qemu-kvm) | RHSA-2014:0927 | 2014-07-23 |
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6 (qemu-kvm-rhev) | RHSA-2014:1187 | 2014-09-15 |
Red Hat Enterprise Linux 6 (qemu-kvm) | RHSA-2014:1075 | 2014-08-19 |
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7 (qemu-kvm-rhev) | RHSA-2014:1268 | 2014-09-22 |
RHEV Hypervisor for RHEL-6 (rhev-hypervisor6) | RHSA-2014:1168 | 2014-09-09 |
RHEV Agents (vdsm) (qemu-kvm-rhev) | RHSA-2014:1076 | 2014-08-19 |
Platform | Package | State |
---|---|---|
Red Hat Enterprise Linux 5 | kvm | Fix deferred |