It was found that vdsm before version 4.20.37 invokes qemu-img on untrusted inputs without limiting resources. By uploading a specially crafted image, an attacker could cause the qemu-img process to consume unbounded amounts of memory of CPU time, causing a denial of service condition that could potentially impact other users of the host.
2018-08-09T19:29:00.207
2024-11-21T03:42:16.757
Modified
CVSSv3.0: 6.5 (MEDIUM)
AV:N/AC:M/Au:N/C:N/I:N/A:C
8.6
6.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | ovirt | vdsm | < 4.20.37 | Yes |
Application | redhat | virtualization | 4.0 | Yes |