CVE-2014-5263

Publication date 26 August 2014

Last updated 24 July 2024


Ubuntu priority

vmstate_xhci_event in hw/usb/hcd-xhci.c in QEMU 1.6.0 does not terminate the list with the VMSTATE_END_OF_LIST macro, which allows attackers to cause a denial of service (out-of-bounds access, infinite loop, and memory corruption) and possibly gain privileges via unspecified vectors.

Read the notes from the security team

Status

Package Ubuntu Release Status
qemu 14.10 utopic
Not affected
14.04 LTS trusty
Fixed 2.0.0+dfsg-2ubuntu1.7
12.04 LTS precise Not in release
10.04 LTS lucid Not in release
qemu-kvm 14.10 utopic Not in release
14.04 LTS trusty Not in release
12.04 LTS precise
Not affected
10.04 LTS lucid
Not affected

Notes


mdeslaur

only 1.6.x and higher

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
qemu

References

Related Ubuntu Security Notices (USN)

    • USN-2409-1
    • QEMU vulnerabilities
    • 13 November 2014

Other references