CVE-2014-5388: Canonical Ubuntu Linux

Medium severity, CVSS 4.6. EPSS: 0.4% chance of exploitation in the next 30 days.

Off-by-one error in the pci_read function in the ACPI PCI hotplug interface (hw/acpi/pcihp.c) in QEMU allows local guest users to obtain sensitive information and have other unspecified impact related to a crafted PCI device that triggers memory corruption.

Affected products

  • Canonical Ubuntu Linux: version 10.04 only; version 12.04 only; version 14.04 only; version 14.10 only
  • Qemu Qemu: up to and including 2.1.3

Published 2014-11-15. Last modified 2026-06-17.