CVE-2014-0148: Qemu

Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.

Qemu before 2.0 block driver for Hyper-V VHDX Images is vulnerable to infinite loops and other potential issues when calculating BAT entries, due to missing bounds checks for block_size and logical_sector_size variables. These are used to derive other fields like 'sectors_per_block' etc. A user able to alter the Qemu disk image could ise this flaw to crash the Qemu instance resulting in DoS.

Affected products

  • Qemu Qemu: before 2.0.0 (fixed in 2.0.0)
  • Red Hat Enterprise Linux Desktop: version 6.0 only
  • Red Hat Enterprise Linux Eus: version 6.5 only
  • Red Hat Enterprise Linux Openstack Platform: version 5 only
  • Red Hat Enterprise Linux Server: version 6.0 only
  • Red Hat Enterprise Linux Server Aus: version 6.5 only
  • Red Hat Enterprise Linux Server Tus: version 6.5 only
  • Red Hat Enterprise Linux Workstation: version 6.0 only
  • Red Hat Virtualization: version 3.0 only

Published 2022-09-29. Last modified 2026-06-17.