CVE Vulnerabilities

CVE-2014-0148

Loop with Unreachable Exit Condition ('Infinite Loop')

Published: Sep 29, 2022 | Modified: Feb 13, 2023
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
4.7 LOW
AV:L/AC:M/Au:N/C:N/I:N/A:C
RedHat/V3
Ubuntu
MEDIUM

Qemu before 2.0 block driver for Hyper-V VHDX Images is vulnerable to infinite loops and other potential issues when calculating BAT entries, due to missing bounds checks for block_size and logical_sector_size variables. These are used to derive other fields like sectors_per_block etc. A user able to alter the Qemu disk image could ise this flaw to crash the Qemu instance resulting in DoS.

Weakness

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Affected Software

Name Vendor Start Version End Version
Qemu Qemu * 2.0.0 (excluding)
OpenStack 3 for RHEL 6 RedHat qemu-kvm-rhev-2:0.12.1.2-2.415.el6_5.8 *
OpenStack 4 for RHEL 6 RedHat qemu-kvm-rhev-2:0.12.1.2-2.415.el6_5.8 *
Red Hat Enterprise Linux 6 RedHat qemu-kvm-2:0.12.1.2-2.415.el6_5.8 *
RHEV 3.X Hypervisor and Agents for RHEL-6 RedHat qemu-kvm-rhev-2:0.12.1.2-2.415.el6_5.8 *
RHEV 3.X Hypervisor and Agents for RHEL-6 RedHat rhev-hypervisor6-0:6.5-20140603.2.el6ev *
Qemu Ubuntu saucy *
Qemu Ubuntu upstream *

References