Wind River Support Network

HomeDefectsLIN1021-10132
Fixed

LIN1021-10132 : Security Advisory - qemu - CVE-2024-4467

Created: Jul 2, 2024    Updated: Dec 2, 2024
Resolved Date: Dec 1, 2024
Found In Version: 10.21.20.1
Severity: Standard
Applicable for: Wind River Linux LTS 21
Component/s: Userspace

Description

A flaw was found in the QEMU disk image utility (qemu-img) 'info' command. A specially crafted image file containing a `json:{}` value describing block devices in QMP could cause the qemu-img process on the host to consume large amounts of memory or CPU time, leading to denial of service or read/write to an existing external file.

CREATE(Triage):(User=admin) CVE-2024-4467 (https://nvd.nist.gov/vuln/detail/CVE-2024-4467)

CVEs


Live chat
Online