cbcvebase.
CVE-2013-4587
published 2013-12-14

CVE-2013-4587: Array index error in the kvm_vm_ioctl_create_vcpu function in virt/kvm/kvm_main.c in the KVM subsystem in the Linux kernel through 3.12.5 allows local users to…

PriorityP429high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.53%
41.9th percentile
Array index error in the kvm_vm_ioctl_create_vcpu function in virt/kvm/kvm_main.c in the KVM subsystem in the Linux kernel through 3.12.5 allows local users to gain privileges via a large id value.

Affected

12 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 3.12.5-1 (bookworm)linux 3.12.5-1 (bookworm)
linuxlinux_kernel< 3.2.543.2.54
linuxlinux_kernel>= 0 < 3.12.5-13.12.5-1
linuxlinux_kernel>= 0 < 3.12.5-13.12.5-1
linuxlinux_kernel>= 0 < 3.12.5-13.12.5-1
linuxlinux_kernel>= 0 < 3.12.5-13.12.5-1
linuxlinux_kernel>= 3.11 < 3.12.63.12.6
linuxlinux_kernel>= 3.3 < 3.4.753.4.75
linuxlinux_kernel>= 3.5 < 3.10.253.10.25
opensuseopensuse
opensuseopensuse
opensuseopensuse

CVSS provenance

nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.2HIGH
vendor_debian7.2HIGH
vendor_redhat7.2HIGH
vendor_ubuntu7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.