cbcvebase.
CVE-2013-7336
published 2014-05-07

CVE-2013-7336: The qemuMigrationWaitForSpice function in qemu/qemu_migration.c in libvirt before 1.1.3 does not properly enter a monitor when performing seamless SPICE…

PriorityP46low1.9CVSS 2.0
AVLACMAuNCNINAP
EPSS
0.33%
25.0th percentile
The qemuMigrationWaitForSpice function in qemu/qemu_migration.c in libvirt before 1.1.3 does not properly enter a monitor when performing seamless SPICE migration, which allows local users to cause a denial of service (NULL pointer dereference and libvirtd crash) by causing domblkstat to be called at the same time as the qemuMonitorGetSpiceMigrationStatus function.

Affected

22 ranges
VendorProductVersion rangeFixed in
debianlibvirt< libvirt 1.1.4-1 (bookworm)libvirt 1.1.4-1 (bookworm)
opensuseopensuse
redhatlibvirt<= 1.1.2
redhatlibvirt
redhatlibvirt
redhatlibvirt
redhatlibvirt
redhatlibvirt
redhatlibvirt
redhatlibvirt
redhatlibvirt
redhatlibvirt
redhatlibvirt
redhatlibvirt
redhatlibvirt
redhatlibvirt
redhatlibvirt
redhatlibvirt
redhatlibvirt>= 0 < 1.1.4-11.1.4-1
redhatlibvirt>= 0 < 1.1.4-11.1.4-1
redhatlibvirt>= 0 < 1.1.4-11.1.4-1
redhatlibvirt>= 0 < 1.1.4-11.1.4-1

CVSS provenance

nvdv2.01.9LOWAV:L/AC:M/Au:N/C:N/I:N/A:P
osv1.9LOW
vendor_ubuntu5.8MEDIUM
vendor_debian1.9LOW
vendor_redhat1.9LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.