CVE-2014-0144
QEMU vulnerability analysis and mitigation

Overview

CVE-2014-0144 affects QEMU block drivers for CLOOP, QCOW2 version 2, and various other image formats in versions before 2.0.0. The vulnerability was discovered by multiple Red Hat researchers including Fam Zheng, Jeff Cody, Kevin Wolf, and Stefan Hajnoczi (CVE Details, Red Hat Bugzilla).

Technical details

The vulnerability stems from missing input validations in various QEMU block drivers, which could lead to potential memory corruptions, integer/buffer overflows, or system crashes. The issue specifically affects multiple components including QCOW2 version 2's active L1 table offset and size, snapshot table offset/size, refcount table size, backing file offset, and header length, as well as validation issues in curl, VDI, VPC/VHD, and CLOOP image formats (Red Hat Bugzilla).

Impact

An attacker with the ability to modify disk image files loaded by a guest could exploit this vulnerability to crash the guest, corrupt QEMU process memory on the host, or potentially execute arbitrary code on the host with the privileges of the QEMU process (Red Hat Advisory).

Mitigation and workarounds

Red Hat has released security updates to address this vulnerability in their Enterprise Linux 6 systems. Users are advised to upgrade to the updated packages. After installing the update, all running virtual machines must be shut down and restarted for the fix to take effect (Red Hat Advisory).

Additional resources


SourceThis report was generated using AI

Related QEMU vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2024-7730HIGH7.8
  • NixOSNixOS
  • qemu
NoYesNov 14, 2024
CVE-2025-11234HIGH7.5
  • CBL MarinerCBL Mariner
  • qemu-kvm-device-display-virtio-gpu
NoYesOct 03, 2025
CVE-2025-12464MEDIUM6.2
  • WolfiWolfi
  • qemu
NoYesOct 31, 2025
CVE-2025-54567MEDIUM4.2
  • WolfiWolfi
  • qemu-pr-helper
NoYesJul 25, 2025
CVE-2025-54566MEDIUM4.2
  • WolfiWolfi
  • qemu-kvm-device-display-virtio-gpu-ccw
NoYesJul 25, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management