CVE-2013-4377Qemu vulnerability

CWE-3998 documents7 sources
Severity
2.3LOWNVD
EPSS
0.1%
top 72.34%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 11
Latest updateMay 17

Description

Use-after-free vulnerability in the virtio-pci implementation in Qemu 1.4.0 through 1.6.0 allows local users to cause a denial of service (daemon crash) by "hot-unplugging" a virtio device.

CVSS vector

AV:A/AC:M/C:N/I:N/A:PExploitability: 4.4 | Impact: 2.9

Affected Packages3 packages

debiandebian/qemu< qemu 1.7.0+dfsg-4 (bookworm)
Debianqemu/qemu< 1.7.0+dfsg-4+3
NVDqemu/qemu8 versions+7

Patches

🔴Vulnerability Details

2
GHSA
GHSA-rr2r-jfm5-mmxg: Use-after-free vulnerability in the virtio-pci implementation in Qemu 12022-05-17
OSV
CVE-2013-4377: Use-after-free vulnerability in the virtio-pci implementation in Qemu 12013-10-11

📋Vendor Advisories

3
Ubuntu
QEMU vulnerabilities2014-01-30
Red Hat
qemu: hot-unplugging virtio devices in guest can crash host qemu process2013-07-11
Debian
CVE-2013-4377: qemu - Use-after-free vulnerability in the virtio-pci implementation in Qemu 1.4.0 thro...2013

💬Community

2
Bugzilla
CVE-2013-4377 qemu: hot-unplugging virtio devices in guest can crash host qemu process2013-09-26
Bugzilla
CVE-2013-4377: qemu: hot-unplugging virtio devices in guest can crash host qemu process [fedora-all]2013-09-26