CVE-2013-4535
published 2020-02-11CVE-2013-4535: The virtqueue_map_sg function in hw/virtio/virtio.c in QEMU before 1.7.2 allows remote attackers to execute arbitrary files via a crafted savevm image, related…
PriorityP345high8.8CVSS 3.1
AVLACLPRLUINSCCHIHAH
EPSS
0.96%
57.5th percentile
The virtqueue_map_sg function in hw/virtio/virtio.c in QEMU before 1.7.2 allows remote attackers to execute arbitrary files via a crafted savevm image, related to virtio-block or virtio-serial read.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | qemu | < qemu 2.1+dfsg-1 (bookworm) | qemu 2.1+dfsg-1 (bookworm) |
| qemu | qemu | < 1.7.2 | 1.7.2 |
| qemu | qemu | — | — |
| qemu | qemu | >= 0 < 2.1+dfsg-1 | 2.1+dfsg-1 |
| qemu | qemu | >= 0 < 2.1+dfsg-1 | 2.1+dfsg-1 |
| qemu | qemu | >= 0 < 2.1+dfsg-1 | 2.1+dfsg-1 |
| qemu | qemu | >= 0 < 2.1+dfsg-1 | 2.1+dfsg-1 |
| qemu | qemu | >= 0 < 2.0.0+dfsg-2ubuntu1.3 | 2.0.0+dfsg-2ubuntu1.3 |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | virtualization | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv8.8HIGH
vendor_debian8.8LOW
vendor_redhat8.8HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
QEMU vulnerabilities
vendor_ubuntu·2014-09-08·CVSS 7.5
CVE-2013-4148 [HIGH] QEMU vulnerabilities
Title: QEMU vulnerabilities
Summary: Several security issues were fixed in QEMU.
Michael S. Tsirkin, Anthony Liguori, and Michael Roth discovered multiple
issues with QEMU state loading after migration. An attacker able to modify
the state data could use these issues to cause a denial of service, or
possibly execute arbitrary code. (CVE-2013-4148, CVE-2013-4149,
CVE-2013-4150, CVE-2013-4151, CVE-2013-4526, CVE-2013-4527, CVE-2013-4529,
CVE-2013-4530, CVE-2013-4531, CVE-2013-4532, CVE-2013-4533, CVE-2013-4534,
CVE-2013-4535, CVE-2013-4536, CVE-2013-4537, CVE-2013-4538, CVE-2013-4539,
CVE-2013-4540, CVE-2013-4541, CVE-2013-4542, CVE-2013-6399, CVE-2014-0182,
CVE-2014-3461)
Kevin Wolf, Stefan Hajnoczi, Fam Zheng, Jeff Cody, Stefan Hajnoczi, and
others discovered multiple issues in the QEMU
Red Hat
qemu: virtio: insufficient validation of num_sg when mapping
vendor_redhat·2013-12-03·CVSS 8.8
CVE-2013-4535 [HIGH] CWE-119 qemu: virtio: insufficient validation of num_sg when mapping
qemu: virtio: insufficient validation of num_sg when mapping
The virtqueue_map_sg function in hw/virtio/virtio.c in QEMU before 1.7.2 allows remote attackers to execute arbitrary files via a crafted savevm image, related to virtio-block or virtio-serial read.
Package: kvm (Red Hat Enterprise Linux 5) - Will not fix
Package: qemu-kvm-rhev (Red Hat Enterprise Linux 6) - Affected
Debian
CVE-2013-4535: qemu - The virtqueue_map_sg function in hw/virtio/virtio.c in QEMU before 1.7.2 allows ...
vendor_debian·2013·CVSS 8.8
CVE-2013-4535 [HIGH] CVE-2013-4535: qemu - The virtqueue_map_sg function in hw/virtio/virtio.c in QEMU before 1.7.2 allows ...
The virtqueue_map_sg function in hw/virtio/virtio.c in QEMU before 1.7.2 allows remote attackers to execute arbitrary files via a crafted savevm image, related to virtio-block or virtio-serial read.
Scope: local
bookworm: resolved (fixed in 2.1+dfsg-1)
bullseye: resolved (fixed in 2.1+dfsg-1)
forky: resolved (fixed in 2.1+dfsg-1)
sid: resolved (fixed in 2.1+dfsg-1)
trixie: resolved (fixed in 2.1+dfsg-1)
GHSA
GHSA-4g6m-vjr9-mv9r: The virtqueue_map_sg function in hw/virtio/virtio
ghsa_unreviewed·2022-05-05
CVE-2013-4535 [HIGH] GHSA-4g6m-vjr9-mv9r: The virtqueue_map_sg function in hw/virtio/virtio
The virtqueue_map_sg function in hw/virtio/virtio.c in QEMU before 1.7.2 allows remote attackers to execute arbitrary files via a crafted savevm image, related to virtio-block or virtio-serial read.
OSV
CVE-2013-4535: The virtqueue_map_sg function in hw/virtio/virtio
osv·2020-02-11·CVSS 8.8
CVE-2013-4535 [HIGH] CVE-2013-4535: The virtqueue_map_sg function in hw/virtio/virtio
The virtqueue_map_sg function in hw/virtio/virtio.c in QEMU before 1.7.2 allows remote attackers to execute arbitrary files via a crafted savevm image, related to virtio-block or virtio-serial read.
OSV
qemu, qemu-kvm vulnerabilities
osv·2014-09-08·CVSS 7.5
CVE-2013-4148 [HIGH] qemu, qemu-kvm vulnerabilities
qemu, qemu-kvm vulnerabilities
Michael S. Tsirkin, Anthony Liguori, and Michael Roth discovered multiple
issues with QEMU state loading after migration. An attacker able to modify
the state data could use these issues to cause a denial of service, or
possibly execute arbitrary code. (CVE-2013-4148, CVE-2013-4149,
CVE-2013-4150, CVE-2013-4151, CVE-2013-4526, CVE-2013-4527, CVE-2013-4529,
CVE-2013-4530, CVE-2013-4531, CVE-2013-4532, CVE-2013-4533, CVE-2013-4534,
CVE-2013-4535, CVE-2013-4536, CVE-2013-4537, CVE-2013-4538, CVE-2013-4539,
CVE-2013-4540, CVE-2013-4541, CVE-2013-4542, CVE-2013-6399, CVE-2014-0182,
CVE-2014-3461)
Kevin Wolf, Stefan Hajnoczi, Fam Zheng, Jeff Cody, Stefan Hajnoczi, and
others discovered multiple issues in the QEMU block drivers. An attacker
able to modify disk ima
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-4535 CVE-2013-4536 qemu: virtio: insufficient validation of num_sg when mapping [fedora-all]
bugzilla·2014-05-08·CVSS 8.8
CVE-2013-4535 [HIGH] CVE-2013-4535 CVE-2013-4536 qemu: virtio: insufficient validation of num_sg when mapping [fedora-all]
CVE-2013-4535 CVE-2013-4536 qemu: virtio: insufficient validation of num_sg when mapping [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
NOTE: this
Bugzilla
CVE-2013-4535 CVE-2013-4536 qemu: virtio: insufficient validation of num_sg when mapping
bugzilla·2014-02-18·CVSS 8.8
CVE-2013-4535 [HIGH] CVE-2013-4535 CVE-2013-4536 qemu: virtio: insufficient validation of num_sg when mapping
CVE-2013-4535 CVE-2013-4536 qemu: virtio: insufficient validation of num_sg when mapping
Both virtio-block and virtio-serial read, VirtQueueElements are read in as
buffers, and passed to virtqueue_map_sg(), where num_sg is taken from the
wire and can force writes to indicies beyond VIRTQUEUE_MAX_SIZE.
An user able to alter the savevm data (either on the disk or over the wire
during migration) could use this flaw to to corrupt QEMU process memory on
the (destination) host, which could potentially result in arbitrary code
execution on the host with the privileges of the QEMU process.
Upstream fix:
-> http://git.qemu.org/?p=qemu.git;a=commit;h=36cf2a37132c7f01fa9adb5f95f5312b27742fd4
Discussion:
Statement:
This issue does affect the versions of kvm package as shipped with
Red Hat Enterp
http://git.qemu.org/?p=qemu.git%3Ba=commitdiff%3Bh=36cf2a37132c7f01fa9adb5f95f5312b27742fd4http://lists.fedoraproject.org/pipermail/package-announce/2014-May/133345.htmlhttp://lists.nongnu.org/archive/html/qemu-stable/2014-07/msg00187.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0743.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0744.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1066401http://git.qemu.org/?p=qemu.git%3Ba=commitdiff%3Bh=36cf2a37132c7f01fa9adb5f95f5312b27742fd4http://lists.fedoraproject.org/pipermail/package-announce/2014-May/133345.htmlhttp://lists.nongnu.org/archive/html/qemu-stable/2014-07/msg00187.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0743.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0744.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1066401
2020-02-11
Published