High severity8.8NVD Advisory· Published Feb 11, 2020· Updated Jun 16, 2026
CVE-2013-4535
CVE-2013-4535
Description
The virtqueue_map_sg function in hw/virtio/virtio.c in QEMU before 1.7.2 allows remote attackers to execute arbitrary files via a crafted savevm image, related to virtio-block or virtio-serial read.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
9- cpe:2.3:a:redhat:virtualization:3.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_server_tus:6.5:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
6- lists.fedoraproject.org/pipermail/package-announce/2014-May/133345.htmlnvdThird Party Advisory
- lists.nongnu.org/archive/html/qemu-stable/2014-07/msg00187.htmlnvdThird Party Advisory
- rhn.redhat.com/errata/RHSA-2014-0743.htmlnvdThird Party Advisory
- rhn.redhat.com/errata/RHSA-2014-0744.htmlnvdThird Party Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingThird Party Advisory
- git.qemu.orgnvd
News mentions
0No linked articles in our index yet.