CVE-2014-0144: Qemu

High severity, CVSS 8.6. EPSS: 1% chance of exploitation in the next 30 days.

QEMU before 2.0.0 block drivers for CLOOP, QCOW2 version 2 and various other image formats are vulnerable to potential memory corruptions, integer/buffer overflows or crash caused by missing input validations which could allow a remote user to execute arbitrary code on the host with the privileges of the QEMU process.

Affected products

  • Qemu Qemu: before 2.0.0 (fixed in 2.0.0)
  • Red Hat Enterprise Linux Desktop: version 6.0 only
  • Red Hat Enterprise Linux Eus: version 6.5 only
  • Red Hat Enterprise Linux Openstack Platform: version 5 only
  • Red Hat Enterprise Linux Server: version 6.0 only
  • Red Hat Enterprise Linux Server Aus: version 6.5 only
  • Red Hat Enterprise Linux Server Tus: version 6.5 only
  • Red Hat Enterprise Linux Workstation: version 6.0 only
  • Red Hat Virtualization: version 3.0 only

Published 2022-09-29. Last modified 2026-06-17.