CVE-2024-4467 Information
Jul 04, 2024
cve
Description
A flaw was found in the QEMU disk image utility (qemu-img) ‘info’ command. A specially crafted image file containing a json: value describing block devices in QMP could cause the qemu-img process on the host to consume large amounts of memory or CPU time leading to denial of service or read/write to an existing external file.
Reference
https://access.redhat.com/security/cve/CVE-2024-4467 https://bugzilla.redhat.com/show_bug.cgi?id=2278875 https://access.redhat.com/errata/RHSA-2024:4276 https://access.redhat.com/errata/RHSA-2024:4277 https://access.redhat.com/errata/RHSA-2024:4278
Share on: