Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-4467

Опубликовано: 02 июл. 2024
Источник: debian
EPSS Низкий

Описание

A flaw was found in the QEMU disk image utility (qemu-img) 'info' command. A specially crafted image file containing a `json:{}` value describing block devices in QMP could cause the qemu-img process on the host to consume large amounts of memory or CPU time, leading to denial of service or read/write to an existing external file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
qemufixed1:9.0.1+ds-1package
qemufixed1:7.2+dfsg-7+deb12u7bookwormpackage
qemuignoredbullseyepackage

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=2278875

  • https://gitlab.com/qemu-project/qemu/-/commit/bd385a5298d7062668e804d73944d52aec9549f1

  • https://gitlab.com/qemu-project/qemu/-/commit/2eb42a728d27a43fdcad5f37d3f65706ce6deba5

  • https://gitlab.com/qemu-project/qemu/-/commit/7e1110664ecbc4826f3c978ccb06b6c1bce823e6

  • https://gitlab.com/qemu-project/qemu/-/commit/7ead946998610657d38d1a505d5f25300d4ca613

EPSS

Процентиль: 22%
0.00069
Низкий

Связанные уязвимости

CVSS3: 7.8
ubuntu
12 месяцев назад

A flaw was found in the QEMU disk image utility (qemu-img) 'info' command. A specially crafted image file containing a `json:{}` value describing block devices in QMP could cause the qemu-img process on the host to consume large amounts of memory or CPU time, leading to denial of service or read/write to an existing external file.

CVSS3: 7.8
redhat
12 месяцев назад

A flaw was found in the QEMU disk image utility (qemu-img) 'info' command. A specially crafted image file containing a `json:{}` value describing block devices in QMP could cause the qemu-img process on the host to consume large amounts of memory or CPU time, leading to denial of service or read/write to an existing external file.

CVSS3: 7.8
nvd
12 месяцев назад

A flaw was found in the QEMU disk image utility (qemu-img) 'info' command. A specially crafted image file containing a `json:{}` value describing block devices in QMP could cause the qemu-img process on the host to consume large amounts of memory or CPU time, leading to denial of service or read/write to an existing external file.

CVSS3: 7.8
msrc
около 2 месяцев назад

Описание отсутствует

suse-cvrf
9 месяцев назад

Security update for qemu

EPSS

Процентиль: 22%
0.00069
Низкий