CVE-2014-9718
Vulnerability Summary
Timeline
Description
The (1) BMDMA and (2) AHCI HBA interfaces in the IDE functionality in QEMU 1.0 through 2.1.3 have multiple interpretations of a function's return value, which allows guest OS users to cause a host OS denial of service (memory consumption or infinite loop, and system crash) via a PRDT with zero complete sectors, related to the bmdma_prepare_buf and ahci_dma_prepare_buf functions.
CVSS Metrics
- v2.0•MEDIUM•Score: 4.9AV:L/AC:L/Au:N/C:N/I:N/A:C
EPSS Trends
Current EPSS score: 0.21%• Percentile: 43%
Techniques & Countermeasures
- CWE-399•Resource Management Errors
Weaknesses in this category are related to improper management of system resources.
Affected Systems
- debian•debian_linux
8.0
- qemu•qemu
1.0 | 1.0:rc1 | 1.0:rc2 | 1.0:rc3 | 1.0:rc4 | 1.0.1 | 1.1 | 1.1:rc1 | 1.1:rc2 | 1.1:rc3 | 1.1:rc4 | 1.4.1 | 1.4.2 | 1.5.0 | 1.5.0:rc1 | 1.5.0:rc2 | 1.5.0:rc3 | 1.5.1 | 1.5.2 | 1.5.3 | 1.6.0 | 1.6.0:rc1 | 1.6.0:rc2 | 1.6.0:rc3 | 1.6.1 | 1.6.2 | 1.7.1 | 2.0.0 | 2.0.0:rc0 | 2.0.0:rc1 | 2.0.0:rc2 | 2.0.0:rc3 | 2.0.2 | 2.1.0 | 2.1.0:rc0 | 2.1.0:rc1 | 2.1.0:rc2 | 2.1.0:rc3 | 2.1.0:rc5 | 2.1.1 | 2.1.2 | 2.1.3