Vulnerability Bulletins

IBM Security Bulletin: Vulnerabilities in qemu-kvm (CVE-2014-0222, CVE-2014-0223)

   
Affected software IBM
 
KVM (Kernel-based Virtual Machine) is a full virtualization solution for Linux on AMD64 and Intel 64 systems. The qemu-kvm package provides the user-space component for running virtual machines using KVM. Two integer overflow flaws were found in the QEMU block driver for QCOW version 1 disk images. A user able to alter the QEMU disk image files loaded by a guest could use either of these flaws to corrupt QEMU process memory on the host, which could potentially result in arbitrary code

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_vulnerabilities_in_qemu_kvm_cve_2014_0222_cve_2014_0223?lang=en_us