Loading HuntDB...

GHSA-5cwv-6xqx-92m5

GitHub Security Advisory

⚠ Unreviewed HIGH Has CVE

Advisory Details

A flaw was found in the QEMU disk image utility (qemu-img) 'info' command. A specially crafted image file containing a `json:{}` value describing block devices in QMP could cause the qemu-img process on the host to consume large amounts of memory or CPU time, leading to denial of service or read/write to an existing external file.

Related CVEs

Key Information

GHSA ID
GHSA-5cwv-6xqx-92m5
Published
July 2, 2024 9:32 PM
Last Modified
July 23, 2024 6:31 PM
CVSS Score
7.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: June 18, 2025 6:25 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.