HomeDefectsLIN1024-2503
Fixed

LIN1024-2503 : Security Advisory - qemu - CVE-2024-4467

Created: Jul 2, 2024    Updated: Aug 28, 2024
Resolved Date: Aug 18, 2024
Found In Version: 10.24.33.1
Fix Version: 10.24.33.1
Severity: Standard
Applicable for: Wind River Linux LTS 24
Component/s: Userspace

Description

A flaw was found in the QEMU disk image utility (qemu-img) 'info' command. A specially crafted image file containing a `json:{}` value describing block devices in QMP could cause the qemu-img process on the host to consume large amounts of memory or CPU time, leading to denial of service or read/write to an existing external file.

CREATE(Triage):(User=admin) CVE-2024-4467 (https://nvd.nist.gov/vuln/detail/CVE-2024-4467)

CVEs