CVE Vulnerabilities

CVE-2014-0148

Loop with Unreachable Exit Condition ('Infinite Loop')

Published: Sep 29, 2022 | Modified: Nov 21, 2024
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
4.7 LOW
AV:L/AC:M/Au:N/C:N/I:N/A:C
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Qemu before 2.0 block driver for Hyper-V VHDX Images is vulnerable to infinite loops and other potential issues when calculating BAT entries, due to missing bounds checks for block_size and logical_sector_size variables. These are used to derive other fields like sectors_per_block etc. A user able to alter the Qemu disk image could ise this flaw to crash the Qemu instance resulting in DoS.

Weakness

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Affected Software

NameVendorStart VersionEnd Version
QemuQemu*2.0.0 (excluding)
OpenStack 3 for RHEL 6RedHatqemu-kvm-rhev-2:0.12.1.2-2.415.el6_5.8*
OpenStack 4 for RHEL 6RedHatqemu-kvm-rhev-2:0.12.1.2-2.415.el6_5.8*
Red Hat Enterprise Linux 6RedHatqemu-kvm-2:0.12.1.2-2.415.el6_5.8*
RHEV 3.X Hypervisor and Agents for RHEL-6RedHatqemu-kvm-rhev-2:0.12.1.2-2.415.el6_5.8*
RHEV 3.X Hypervisor and Agents for RHEL-6RedHatrhev-hypervisor6-0:6.5-20140603.2.el6ev*
QemuUbuntusaucy*
QemuUbuntuupstream*

References