UBUNTU-CVE-2014-9718

    Dashboard / Vulnerabilities / UBUNTU-CVE-2014-9718

    UBUNTU-CVE-2014-9718

    Published: 21 Apr 2015Last Modified: 4 Feb 2026
    Upstream:
    Aliases:

    Summary:

    Details: The (1) BMDMA and (2) AHCI HBA interfaces in the IDE functionality in QEMU 1.0 through 2.1.3 have multiple interpretations of a function's return value, which allows guest OS users to cause a host OS denial of service (memory consumption or infinite loop, and system crash) via a PRDT with zero complete sectors, related to the bmdma_prepare_buf and ahci_dma_prepare_buf functions.

    Affected packages

    Package

    Name: qemu

    Purl: pkg:deb/ubuntu/[email protected]+dfsg-2ubuntu1.17?arch=source&distro=trusty

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -2.0.0+dfsg-2ubuntu1.17

    Affected versions

    1.5.0+dfsg-3ubuntu5
    1.5.0+dfsg-3ubuntu6

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    UBUNTU-CVE-2014-9718 | CVE-DB