cbcvebase.
CVE-2014-0049
published 2014-03-11

CVE-2014-0049: Buffer overflow in the complete_emulated_mmio function in arch/x86/kvm/x86.c in the Linux kernel before 3.13.6 allows guest OS users to execute arbitrary code…

PriorityP335high7.4CVSS 2.0
AVAACMAuSCCICAC
EPSS
0.78%
52.2th percentile
Buffer overflow in the complete_emulated_mmio function in arch/x86/kvm/x86.c in the Linux kernel before 3.13.6 allows guest OS users to execute arbitrary code on the host OS by leveraging a loop that triggers an invalid memory copy affecting certain cancel_work_item data.

Affected

6 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 3.13.6-1 (bookworm)linux 3.13.6-1 (bookworm)
linuxlinux_kernel< 3.13.63.13.6
linuxlinux_kernel>= 0 < 3.13.6-13.13.6-1
linuxlinux_kernel>= 0 < 3.13.6-13.13.6-1
linuxlinux_kernel>= 0 < 3.13.6-13.13.6-1
linuxlinux_kernel>= 0 < 3.13.6-13.13.6-1

CVSS provenance

nvdv2.07.4HIGHAV:A/AC:M/Au:S/C:C/I:C/A:C
osv7.4HIGH
vendor_debian7.4HIGH
vendor_redhat7.4HIGH
vendor_ubuntu7.4HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.