Qemu before 2.0 block driver for Hyper-V VHDX Images is vulnerable to infinite loops and other potential issues when calculating BAT entries, due to missing bounds checks for block_size and logical_sector_size variables. These are used to derive other fields like sectors_per_block etc. A user able to alter the Qemu disk image could ise this flaw to crash the Qemu instance resulting in DoS.
The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Qemu | Qemu | * | 2.0.0 (excluding) |
OpenStack 3 for RHEL 6 | RedHat | qemu-kvm-rhev-2:0.12.1.2-2.415.el6_5.8 | * |
OpenStack 4 for RHEL 6 | RedHat | qemu-kvm-rhev-2:0.12.1.2-2.415.el6_5.8 | * |
Red Hat Enterprise Linux 6 | RedHat | qemu-kvm-2:0.12.1.2-2.415.el6_5.8 | * |
RHEV 3.X Hypervisor and Agents for RHEL-6 | RedHat | qemu-kvm-rhev-2:0.12.1.2-2.415.el6_5.8 | * |
RHEV 3.X Hypervisor and Agents for RHEL-6 | RedHat | rhev-hypervisor6-0:6.5-20140603.2.el6ev | * |
Qemu | Ubuntu | saucy | * |
Qemu | Ubuntu | upstream | * |