coldfunction qCUDA qcow.c qcow_make_empty integer overflow

CVE Details

Basic Information

Title coldfunction qCUDA qcow.c qcow_make_empty integer overflow
Type cve
Published 2025-06-25T10:31:05.220Z
Last Seen

Product Information

Vendor coldfunction
Product qCUDA
Version db0085400c2f2011eed46fbc04fdc0873141688e

CVSS Information

Base Score 4.8 (MEDIUM)
Attack Vector CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X
Confidentiality Impact
Integrity Impact
Availability Impact

AI Analysis

AI Description An integer overflow vulnerability in the qcow_make_empty function of qCUDA’s qcow.c file could allow local attackers to cause unintended behavior, potentially leading to system instability or privilege escalation.
AI Severity Medium
Vendor coldfunction
Product qCUDA
Affected Version no specific version available

Affected Products

  • coldfunction qCUDA db0085400c2f2011eed46fbc04fdc0873141688e

Additional Information

CVE List
CWE List CWE-190, CWE-189
Bulletin Family

Description

A vulnerability was found in coldfunction qCUDA up to db0085400c2f2011eed46fbc04fdc0873141688e. It has been rated as problematic. Affected by this issue is the function qcow_make_empty of the file qCUDA/qcu-device/block/qcow.c. The manipulation of the argument s->l1_size leads to integer overflow. The attack needs to be approached locally. This product is using a rolling release to provide continuous delivery. Therefore, no version details for affected nor updated releases are available.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.