Off-by-one error in the cmd_smart function in the smart self test in hw/ide/core.c in QEMU before 2.0 allows local users to have unspecified impact via a SMART EXECUTE OFFLINE command that triggers a buffer underflow and memory corruption.
No PoCs from references.
- https://github.com/cloudpassage-community/vulnerable_image_check
- https://github.com/cloudpassage/vulnerable_image_check