Wind River Support Network

HomeDefectsLIN1021-415
Fixed

LIN1021-415 : Security Advisory - qemu - CVE-2013-4536

Created: May 30, 2021    Updated: May 13, 2022
Resolved Date: Jun 7, 2021
Found In Version: 10.21.20.1
Fix Version: 10.21.20.1
Severity: Standard
Applicable for: Wind River Linux LTS 21
Component/s: Userspace

Description

An user able to alter the savevm data (either on the disk or over the wire during migration) could use this flaw to to corrupt QEMU process memory on the (destination) host, which could potentially result in arbitrary code execution on the host with the privileges of the QEMU process.

CREATE(Triage):(User=admin) CVE-2013-4536 (https://nvd.nist.gov/vuln/detail/CVE-2013-4536)

CVEs


Live chat
Online