Multiple heap-based buffer overflows in the virtio-blk driver (hw/virtio-blk.c) in qemu-kvm 0.14.0 allow local guest users to cause a denial of service (guest crash) and possibly gain privileges via a (1) write request to the virtio_blk_handle_write function or (2) read request to the virtio_blk_handle_read function that is not properly aligned.
2012-06-21T15:55:08.880
2025-04-11T00:51:21.963
Deferred
CVSSv2: 7.4 (HIGH)
AV:A/AC:M/Au:S/C:C/I:C/A:C
4.4
10.0