CVE-2024-4467

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-4467
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-4467.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-4467
Downstream
Related
Published
2024-07-02T16:15:05Z
Modified
2025-08-09T19:01:26Z
Summary
[none]
Details

A flaw was found in the QEMU disk image utility (qemu-img) 'info' command. A specially crafted image file containing a json:{} value describing block devices in QMP could cause the qemu-img process on the host to consume large amounts of memory or CPU time, leading to denial of service or read/write to an existing external file.

References

Affected packages