QEMU, possibly before 2.0.0, allows local users to cause a denial of service (divide-by-zero error and crash) via a zero value in the (1) tracks field to the seektosector function in block/parallels.c or (2) extent_size field in the bochs function in block/bochs.c.
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "qemu",
"binary_version": "2.0.0~rc1+dfsg-0ubuntu3"
},
{
"binary_name": "qemu-common",
"binary_version": "2.0.0~rc1+dfsg-0ubuntu3"
},
{
"binary_name": "qemu-guest-agent",
"binary_version": "2.0.0~rc1+dfsg-0ubuntu3"
},
{
"binary_name": "qemu-keymaps",
"binary_version": "2.0.0~rc1+dfsg-0ubuntu3"
},
{
"binary_name": "qemu-kvm",
"binary_version": "2.0.0~rc1+dfsg-0ubuntu3"
},
{
"binary_name": "qemu-system",
"binary_version": "2.0.0~rc1+dfsg-0ubuntu3"
},
{
"binary_name": "qemu-system-aarch64",
"binary_version": "2.0.0~rc1+dfsg-0ubuntu3"
},
{
"binary_name": "qemu-system-arm",
"binary_version": "2.0.0~rc1+dfsg-0ubuntu3"
},
{
"binary_name": "qemu-system-common",
"binary_version": "2.0.0~rc1+dfsg-0ubuntu3"
},
{
"binary_name": "qemu-system-mips",
"binary_version": "2.0.0~rc1+dfsg-0ubuntu3"
},
{
"binary_name": "qemu-system-misc",
"binary_version": "2.0.0~rc1+dfsg-0ubuntu3"
},
{
"binary_name": "qemu-system-ppc",
"binary_version": "2.0.0~rc1+dfsg-0ubuntu3"
},
{
"binary_name": "qemu-system-sparc",
"binary_version": "2.0.0~rc1+dfsg-0ubuntu3"
},
{
"binary_name": "qemu-system-x86",
"binary_version": "2.0.0~rc1+dfsg-0ubuntu3"
},
{
"binary_name": "qemu-user",
"binary_version": "2.0.0~rc1+dfsg-0ubuntu3"
},
{
"binary_name": "qemu-user-static",
"binary_version": "2.0.0~rc1+dfsg-0ubuntu3"
},
{
"binary_name": "qemu-utils",
"binary_version": "2.0.0~rc1+dfsg-0ubuntu3"
}
]
}