CVE-2013-4536
Last modified
CVE-2013-4536 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. An user able to alter the savevm data (either on the disk or over the wire during migration) could use this flaw to to corrupt QEMU process memory on the (destination) host, which could potentially result in arbitrary code execution on the host with the privileges of the QEMU process.. EPSS estimates a 0.30% chance of exploitation in the next 30 days.
Description
An user able to alter the savevm data (either on the disk or over the wire during migration) could use this flaw to to corrupt QEMU process memory on the (destination) host, which could potentially result in arbitrary code execution on the host with the privileges of the QEMU process.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Qemu | Qemu | < 1.5.3 |
References
- https://bugzilla.redhat.com/show_bug.cgi?id=1066401Issue Tracking, Patch, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20210727-0002/Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1066401Issue Tracking, Patch, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20210727-0002/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2013-4536?
How severe is CVE-2013-4536?
How do I fix CVE-2013-4536?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2013
- CVE-2013-4530Buffer overflow in hw/ssi/pl022.c in QEMU before 1.7.2 allow…
- CVE-2013-4531Buffer overflow in target-arm/machine.c in QEMU before 1.7.2…
- CVE-2013-4532Qemu 1.1.2+dfsg to 2.1+dfsg suffers from a buffer overrun wh…7.8
- CVE-2013-4533Buffer overflow in the pxa2xx_ssp_load function in hw/arm/px…
- CVE-2013-4534Buffer overflow in hw/intc/openpic.c in QEMU before 1.7.2 al…
- CVE-2013-4535The virtqueue_map_sg function in hw/virtio/virtio.c in QEMU …8.8
- CVE-2013-4537The ssi_sd_transfer function in hw/sd/ssi-sd.c in QEMU befor…
- CVE-2013-4538Multiple buffer overflows in the ssd0323_load function in hw…
- CVE-2013-4539Multiple buffer overflows in the tsc210x_load function in hw…
- CVE-2013-4540Buffer overflow in scoop_gpio_handler_update in QEMU before …
- CVE-2013-4541The usb_device_post_load function in hw/usb/bus.c in QEMU be…
- CVE-2013-4542The virtio_scsi_load_request function in hw/scsi/scsi-bus.c …
Are you affected by CVE-2013-4536?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
