CVE-2014-3559

low
Published 2014-08-06 · Modified 2026-05-06
CVSS v3
CVSS v2
3.5
VIR risk
3.5

Description

The oVirt storage backend in Red Hat Enterprise Virtualization 3.4 does not wipe memory snapshots when deleting a VM, even when wipe-after-delete (WAD) is configured for the VM's disk, which allows remote authenticated users with certain credentials to read portions of the deleted VM's memory and obtain sensitive information via an uninitialized storage volume.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://rhn.redhat.com/errata/RHSA-2014-1002.html

Application impact

VendorProductVersionsFixed
redhatenterprise_virtualization3.4

References

CWEs

CWE-264

Verify integrity in audit chain (admin only). AS-IS.