CVE-2014-0147: Fedoraproject Fedora

Medium severity, CVSS 6.2. EPSS: 0.3% chance of exploitation in the next 30 days.

Qemu before 1.6.2 block diver for the various disk image formats used by Bochs and for the QCOW version 2 format, are vulnerable to a possible crash caused by signed data types or a logic error while creating QCOW2 snapshots, which leads to incorrectly calling update_refcount() routine.

Affected products

  • Fedoraproject Fedora: version 20 only
  • Qemu Qemu: before 1.6.2 (fixed in 1.6.2)
  • Red Hat Enterprise Linux Desktop: version 6.0 only
  • Red Hat Enterprise Linux Eus: version 6.5 only
  • Red Hat Enterprise Linux Openstack Platform: version 5 only
  • Red Hat Enterprise Linux Server: version 6.0 only
  • Red Hat Enterprise Linux Server Aus: version 6.5 only
  • Red Hat Enterprise Linux Server Tus: version 6.5 only
  • Red Hat Enterprise Linux Workstation: version 6.0 only
  • Red Hat Virtualization: version 3.0 only

Published 2022-09-29. Last modified 2026-06-17.