CVE-2014-9718

Modified
Published: 21 Apr 2015, 16:00
Last modified:06 Aug 2024, 13:55

Vulnerability Summary

Overall Risk (default)
low
20/100
CVSS Score
4.9 MEDIUM
v2.0 (nvd)
EPSS Score
0.21% LOW
0% probability -0.01%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

21 Apr 2015, 16:00
Published
Vulnerability first disclosed
06 Aug 2024, 13:55
Last Modified
Vulnerability information updated

Description

The (1) BMDMA and (2) AHCI HBA interfaces in the IDE functionality in QEMU 1.0 through 2.1.3 have multiple interpretations of a function's return value, which allows guest OS users to cause a host OS denial of service (memory consumption or infinite loop, and system crash) via a PRDT with zero complete sectors, related to the bmdma_prepare_buf and ahci_dma_prepare_buf functions.

CVSS Metrics

  • v2.0MEDIUMScore: 4.9AV:L/AC:L/Au:N/C:N/I:N/A:C

EPSS Trends

Current EPSS score: 0.21% Percentile: 43%

Techniques & Countermeasures

  • CWE-399Resource Management Errors

    Weaknesses in this category are related to improper management of system resources.

Affected Systems

  • debiandebian_linux

    8.0

  • qemuqemu

    1.0 | 1.0:rc1 | 1.0:rc2 | 1.0:rc3 | 1.0:rc4 | 1.0.1 | 1.1 | 1.1:rc1 | 1.1:rc2 | 1.1:rc3 | 1.1:rc4 | 1.4.1 | 1.4.2 | 1.5.0 | 1.5.0:rc1 | 1.5.0:rc2 | 1.5.0:rc3 | 1.5.1 | 1.5.2 | 1.5.3 | 1.6.0 | 1.6.0:rc1 | 1.6.0:rc2 | 1.6.0:rc3 | 1.6.1 | 1.6.2 | 1.7.1 | 2.0.0 | 2.0.0:rc0 | 2.0.0:rc1 | 2.0.0:rc2 | 2.0.0:rc3 | 2.0.2 | 2.1.0 | 2.1.0:rc0 | 2.1.0:rc1 | 2.1.0:rc2 | 2.1.0:rc3 | 2.1.0:rc5 | 2.1.1 | 2.1.2 | 2.1.3

References (4)