CVE-2014-2894

Related Vulnerabilities: CVE-2014-2894  

Off-by-one error in the cmd_smart function in the smart self test in hw/ide/core.c in QEMU before 2.0 allows local users to have unspecified impact via a SMART EXECUTE OFFLINE command that triggers a buffer underflow and memory corruption.

The MITRE CVE dictionary describes this issue as:

Off-by-one error in the cmd_smart function in the smart self test in hw/ide/core.c in QEMU before 2.0 allows local users to have unspecified impact via a SMART EXECUTE OFFLINE command that triggers a buffer underflow and memory corruption.

Find out more about CVE-2014-2894 from the MITRE CVE dictionary dictionary and NIST NVD.

Statement

This issue does not affect the versions of kvm package as shipped with Red Hat
Enterprise Linux 5.

CVSS v2 metrics

Base Score 4
Base Metrics AV:A/AC:H/Au:S/C:P/I:P/A:P
Access Vector Adjacent Network
Access Complexity High
Authentication Single
Confidentiality Impact Partial
Integrity Impact Partial
Availability Impact Partial

Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).

Red Hat Security Errata

Platform Errata Release Date
Red Hat Enterprise Linux OpenStack Platform 4.0 (qemu-kvm-rhev) RHSA-2014:0888 2014-07-24
Red Hat Enterprise Linux OpenStack Platform 3.0 (qemu-kvm-rhev) RHSA-2014:0888 2014-07-24
RHEV Hypervisor for RHEL-6 (rhev-hypervisor6) RHSA-2014:0674 2014-06-09
Red Hat Enterprise Linux 7 (qemu-kvm) RHSA-2014:0704 2014-06-10
RHEV Agents (vdsm) (qemu-kvm-rhev) RHSA-2014:0744 2014-06-10
Red Hat Enterprise Linux 6 (qemu-kvm) RHSA-2014:0743 2014-06-10

Affected Packages State

Platform Package State
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) qemu-kvm-rhev Will not fix
Red Hat Enterprise Linux 5 kvm Not affected