Qemu block driver for the QCOW version 2 format is vulnerable to a NULL pointer dereference flaw. It could occur in case of an error in reading a qcow2 image file, after the 'snapshot_offset' & 'nb_snapshots' fields have been initialised. An user able to alter the Qemu disk image could use this flaw to crash the Qemu instance resulting in Dos. Upstream fix: ------------- qcow2: Fix NULL dereference in qcow2_open() error path -> http://git.qemu.org/?p=qemu.git;a=commit;h=11b128f4062dd7f89b14abc8877ff20d41b28be9
Acknowledgement: This issue was discovered by Kevin Wolf of Red Hat Inc.
Created qemu tracking bugs for this issue: Affects: fedora-all [bug 1086713]
This issue has been addressed in following products: RHEV-H and Agents for RHEL-6 Via RHSA-2014:0421 https://rhn.redhat.com/errata/RHSA-2014-0421.html
This issue has been addressed in following products: Red Hat Enterprise Linux 6 Via RHSA-2014:0420 https://rhn.redhat.com/errata/RHSA-2014-0420.html
This issue has been addressed in following products: OpenStack 3 for RHEL 6 Via RHSA-2014:0435 https://rhn.redhat.com/errata/RHSA-2014-0435.html
This issue has been addressed in following products: OpenStack 4 for RHEL 6 Via RHSA-2014:0434 https://rhn.redhat.com/errata/RHSA-2014-0434.html
qemu-1.6.2-4.fc20 has been pushed to the Fedora 20 stable repository. If problems still persist, please make note of it in this bug report.
This issue has been addressed in following products: RHEV-H and Agents for RHEL-6 Via RHSA-2014:0674 https://rhn.redhat.com/errata/RHSA-2014-0674.html