Use-after-free vulnerability in the virtio-pci implementation in Qemu 1.4.0 through 1.6.0 allows local users to cause a denial of service (daemon crash) by "hot-unplugging" a virtio device.
2013-10-11T22:55:40.220
2025-04-11T00:51:21.963
Deferred
CVSSv2: 2.3 (LOW)
AV:A/AC:M/Au:S/C:N/I:N/A:P
4.4
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | qemu | qemu | 1.4.0 | Yes |
Application | qemu | qemu | 1.4.1 | Yes |
Application | qemu | qemu | 1.4.2 | Yes |
Application | qemu | qemu | 1.5.0 | Yes |
Application | qemu | qemu | 1.5.0 | Yes |
Application | qemu | qemu | 1.5.0 | Yes |
Application | qemu | qemu | 1.5.0 | Yes |
Application | qemu | qemu | 1.5.1 | Yes |
Application | qemu | qemu | 1.5.2 | Yes |
Application | qemu | qemu | 1.5.3 | Yes |
Application | qemu | qemu | 1.6.0 | Yes |
Application | qemu | qemu | 1.6.0 | Yes |
Application | qemu | qemu | 1.6.0 | Yes |
Application | qemu | qemu | 1.6.0 | Yes |