CVE-2013-4542
published 2014-11-04CVE-2013-4542: The virtio_scsi_load_request function in hw/scsi/scsi-bus.c in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via a crafted savevm…
PriorityP346high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
4.95%
91.2th percentile
The virtio_scsi_load_request function in hw/scsi/scsi-bus.c in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via a crafted savevm image, which triggers an out-of-bounds array access.
Affected
73 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | qemu | < qemu 2.1+dfsg-1 (bookworm) | qemu 2.1+dfsg-1 (bookworm) |
| qemu | qemu | <= 1.7.1 | — |
| qemu | qemu | — | — |
| qemu | qemu | — | — |
| qemu | qemu | — | — |
| qemu | qemu | — | — |
| qemu | qemu | — | — |
| qemu | qemu | — | — |
| qemu | qemu | — | — |
| qemu | qemu | — | — |
| qemu | qemu | — | — |
| qemu | qemu | — | — |
| qemu | qemu | — | — |
| qemu | qemu | — | — |
| qemu | qemu | — | — |
| qemu | qemu | — | — |
| qemu | qemu | — | — |
| qemu | qemu | — | — |
| qemu | qemu | — | — |
| qemu | qemu | — | — |
| qemu | qemu | — | — |
| qemu | qemu | — | — |
| qemu | qemu | — | — |
| qemu | qemu | — | — |
| qemu | qemu | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5LOW
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
QEMU vulnerabilities
vendor_ubuntu·2014-09-08·CVSS 7.5
CVE-2013-4148 [HIGH] QEMU vulnerabilities
Title: QEMU vulnerabilities
Summary: Several security issues were fixed in QEMU.
Michael S. Tsirkin, Anthony Liguori, and Michael Roth discovered multiple
issues with QEMU state loading after migration. An attacker able to modify
the state data could use these issues to cause a denial of service, or
possibly execute arbitrary code. (CVE-2013-4148, CVE-2013-4149,
CVE-2013-4150, CVE-2013-4151, CVE-2013-4526, CVE-2013-4527, CVE-2013-4529,
CVE-2013-4530, CVE-2013-4531, CVE-2013-4532, CVE-2013-4533, CVE-2013-4534,
CVE-2013-4535, CVE-2013-4536, CVE-2013-4537, CVE-2013-4538, CVE-2013-4539,
CVE-2013-4540, CVE-2013-4541, CVE-2013-4542, CVE-2013-6399, CVE-2014-0182,
CVE-2014-3461)
Kevin Wolf, Stefan Hajnoczi, Fam Zheng, Jeff Cody, Stefan Hajnoczi, and
others discovered multiple issues in the QEMU
Red Hat
qemu: virtio-scsi: buffer overrun on invalid state load
vendor_redhat·2013-12-03·CVSS 7.5
CVE-2013-4542 [HIGH] CWE-119 qemu: virtio-scsi: buffer overrun on invalid state load
qemu: virtio-scsi: buffer overrun on invalid state load
The virtio_scsi_load_request function in hw/scsi/scsi-bus.c in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via a crafted savevm image, which triggers an out-of-bounds array access.
Statement: This issue does not affect the versions of kvm package as shipped with
Red Hat Enterprise Linux 5.
This issue does affect the versions of qemu-kvm package as shipped with
Red Hat Enterprise Linux 7.
Package: kvm (Red Hat Enterprise Linux 5) - Not affected
Package: qemu-kvm-rhev (Red Hat Enterprise Linux 6) - Affected
Debian
CVE-2013-4542: qemu - The virtio_scsi_load_request function in hw/scsi/scsi-bus.c in QEMU before 1.7.2...
vendor_debian·2013·CVSS 7.5
CVE-2013-4542 [HIGH] CVE-2013-4542: qemu - The virtio_scsi_load_request function in hw/scsi/scsi-bus.c in QEMU before 1.7.2...
The virtio_scsi_load_request function in hw/scsi/scsi-bus.c in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via a crafted savevm image, which triggers an out-of-bounds array access.
Scope: local
bookworm: resolved (fixed in 2.1+dfsg-1)
bullseye: resolved (fixed in 2.1+dfsg-1)
forky: resolved (fixed in 2.1+dfsg-1)
sid: resolved (fixed in 2.1+dfsg-1)
trixie: resolved (fixed in 2.1+dfsg-1)
GHSA
GHSA-77m2-2x4h-2jg6: The virtio_scsi_load_request function in hw/scsi/scsi-bus
ghsa_unreviewed·2022-05-13
CVE-2013-4542 [HIGH] CWE-119 GHSA-77m2-2x4h-2jg6: The virtio_scsi_load_request function in hw/scsi/scsi-bus
The virtio_scsi_load_request function in hw/scsi/scsi-bus.c in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via a crafted savevm image, which triggers an out-of-bounds array access.
OSV
CVE-2013-4542: The virtio_scsi_load_request function in hw/scsi/scsi-bus
osv·2014-11-04·CVSS 7.5
CVE-2013-4542 [HIGH] CVE-2013-4542: The virtio_scsi_load_request function in hw/scsi/scsi-bus
The virtio_scsi_load_request function in hw/scsi/scsi-bus.c in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via a crafted savevm image, which triggers an out-of-bounds array access.
OSV
qemu, qemu-kvm vulnerabilities
osv·2014-09-08·CVSS 7.5
CVE-2013-4148 [HIGH] qemu, qemu-kvm vulnerabilities
qemu, qemu-kvm vulnerabilities
Michael S. Tsirkin, Anthony Liguori, and Michael Roth discovered multiple
issues with QEMU state loading after migration. An attacker able to modify
the state data could use these issues to cause a denial of service, or
possibly execute arbitrary code. (CVE-2013-4148, CVE-2013-4149,
CVE-2013-4150, CVE-2013-4151, CVE-2013-4526, CVE-2013-4527, CVE-2013-4529,
CVE-2013-4530, CVE-2013-4531, CVE-2013-4532, CVE-2013-4533, CVE-2013-4534,
CVE-2013-4535, CVE-2013-4536, CVE-2013-4537, CVE-2013-4538, CVE-2013-4539,
CVE-2013-4540, CVE-2013-4541, CVE-2013-4542, CVE-2013-6399, CVE-2014-0182,
CVE-2014-3461)
Kevin Wolf, Stefan Hajnoczi, Fam Zheng, Jeff Cody, Stefan Hajnoczi, and
others discovered multiple issues in the QEMU block drivers. An attacker
able to modify disk ima
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-4542 qemu: virtio-scsi: buffer overrun on invalid state load [fedora-all]
bugzilla·2014-05-08·CVSS 7.5
CVE-2013-4542 [HIGH] CVE-2013-4542 qemu: virtio-scsi: buffer overrun on invalid state load [fedora-all]
CVE-2013-4542 qemu: virtio-scsi: buffer overrun on invalid state load [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
NOTE: this issue affects mult
Bugzilla
CVE-2013-4542 qemu: virtio-scsi: buffer overrun on invalid state load
bugzilla·2014-02-18·CVSS 7.5
CVE-2013-4542 [HIGH] CVE-2013-4542 qemu: virtio-scsi: buffer overrun on invalid state load
CVE-2013-4542 qemu: virtio-scsi: buffer overrun on invalid state load
Michael S. Tsirkin writes:
hw/scsi/scsi-bus.c invokes load_request.
virtio_scsi_load_request does:
qemu_get_buffer(f, (unsigned char *)&req->elem, sizeof(req->elem));
this probably can make elem invalid, for example, make in_num or out_num
out-of-bounds, later leading to buffer overrun.
An user able to alter the savevm data (either on the disk or over the wire
during migration) could use this flaw to to corrupt QEMU process memory on
the (destination) host, which could potentially result in arbitrary code
execution on the host with the privileges of the QEMU process.
Upstream fix:
-> http://git.qemu.org/?p=qemu.git;a=commit;h=3c3ce981423e0d6c18af82ee62f1850c2cda5976
Discussion:
Statement:
This issue does not affe
Bugzilla
CVE-2012-4542 kernel: block: default SCSI command filter does not accomodate commands overlap across device classes
bugzilla·2012-11-10·CVSS 4.6
CVE-2012-4542 [MEDIUM] CVE-2012-4542 kernel: block: default SCSI command filter does not accomodate commands overlap across device classes
CVE-2012-4542 kernel: block: default SCSI command filter does not accomodate commands overlap across device classes
The default SCSI command filter does not accomodate commands that overlap across device classes.
An privileged guest user could potentially use this flaw to write arbitrary data to a LUN that is passed-through as read-only.
Acknowledgements:
This issue was discovered by Paolo Bonzini of Red Hat.
Discussion:
The full list of overlapping commands:
- READ SUBCHANNEL UNMAP (destructive, but no control on written data)
- GET PERFORMANCE ERASE (not really a problem, no one supports ERASE anyway)
- READ DISC INFORMATION XPWRITE (not commonly implemented but most dangerous)
---
Proposed upstream patch:
https://lkml.org/lkml/2013/1/24/279
---
This issue has been addressed
http://git.qemu.org/?p=qemu.git%3Ba=commitdiff%3Bh=3c3ce981423e0d6c18af82ee62f1850c2cda5976http://lists.fedoraproject.org/pipermail/package-announce/2014-May/133345.htmlhttp://lists.nongnu.org/archive/html/qemu-stable/2014-07/msg00187.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0743.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0744.htmlhttp://git.qemu.org/?p=qemu.git%3Ba=commitdiff%3Bh=3c3ce981423e0d6c18af82ee62f1850c2cda5976http://lists.fedoraproject.org/pipermail/package-announce/2014-May/133345.htmlhttp://lists.nongnu.org/archive/html/qemu-stable/2014-07/msg00187.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0743.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0744.html
2014-11-04
Published