A flaw was found in the QEMU disk image utility (qemu-img) 'info' command. A specially crafted image file containing a `json:{}` value describing block devices in QMP could cause the qemu-img process on the host to consume large amounts of memory or CPU time, leading to denial of service, or read/write to an existing external file.
Created qemu tracking bugs for this issue: Affects: fedora-all [bug 2295186]
Upstream patch: https://lists.nongnu.org/archive/html/qemu-devel/2024-07/msg00661.html
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions Red Hat Enterprise Linux 8.4 Telecommunications Update Service Via RHSA-2024:4374 https://access.redhat.com/errata/RHSA-2024:4374
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions Red Hat Enterprise Linux 8.6 Telecommunications Update Service Via RHSA-2024:4373 https://access.redhat.com/errata/RHSA-2024:4373
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Extended Update Support Via RHSA-2024:4372 https://access.redhat.com/errata/RHSA-2024:4372
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2024:4420 https://access.redhat.com/errata/RHSA-2024:4420
This issue has been addressed in the following products: Advanced Virtualization for RHEL 8.4.0.EUS Via RHSA-2024:4724 https://access.redhat.com/errata/RHSA-2024:4724