Unrated severityNVD Advisory· Published Oct 4, 2013· Updated Jun 16, 2026
CVE-2013-4344
CVE-2013-4344
Description
Buffer overflow in the SCSI implementation in QEMU, as used in Xen, when a SCSI controller has more than 256 attached devices, allows local users to gain privileges via a small transfer buffer in a REPORT LUNS command.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
11- cpe:2.3:a:redhat:virtualization:3.0:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm:*:*:*+ 2 more
- cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:12.10:*:*:*:*:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:13.10:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
9- lists.opensuse.org/opensuse-security-announce/2014-10/msg00002.htmlnvdMailing ListThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2014-10/msg00003.htmlnvdMailing ListThird Party Advisory
- rhn.redhat.com/errata/RHSA-2013-1553.htmlnvdThird Party Advisory
- rhn.redhat.com/errata/RHSA-2013-1754.htmlnvdThird Party Advisory
- www.openwall.com/lists/oss-security/2013/10/02/2nvdMailing ListThird Party Advisory
- www.securityfocus.com/bid/62773nvdThird Party AdvisoryVDB Entry
- www.ubuntu.com/usn/USN-2092-1nvdThird Party Advisory
- article.gmane.org/gmane.comp.emulators.qemu/237191nvdBroken Link
- osvdb.org/98028nvdBroken Link
News mentions
0No linked articles in our index yet.