QEMU, possibly before 2.0.0, allows local users to cause a denial of service (divide-by-zero error and crash) via a zero value in the (1) tracks field to the seek_to_sector function in block/parallels.c or (2) extent_size field in the bochs function in block/bochs.c.
The product divides a value by zero.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Qemu | Qemu | * | 2.0.0 (including) |
OpenStack 3 for RHEL 6 | RedHat | qemu-kvm-rhev-2:0.12.1.2-2.415.el6_5.8 | * |
OpenStack 4 for RHEL 6 | RedHat | qemu-kvm-rhev-2:0.12.1.2-2.415.el6_5.8 | * |
Red Hat Enterprise Linux 6 | RedHat | qemu-kvm-2:0.12.1.2-2.415.el6_5.8 | * |
RHEV 3.X Hypervisor and Agents for RHEL-6 | RedHat | qemu-kvm-rhev-2:0.12.1.2-2.415.el6_5.8 | * |
RHEV 3.X Hypervisor and Agents for RHEL-6 | RedHat | rhev-hypervisor6-0:6.5-20140603.2.el6ev | * |
Qemu | Ubuntu | saucy | * |
Qemu | Ubuntu | upstream | * |
Qemu-kvm | Ubuntu | lucid | * |
Qemu-kvm | Ubuntu | precise | * |
Qemu-kvm | Ubuntu | quantal | * |