A flaw was found in the way qemu v1.3.0 and later (virtio-rng) validates addresses when guest accesses the config space of a virtio device. If the virtio device has zero/small sized config space, such as virtio-rng, a privileged guest user could use this flaw to access the matching host's qemu address space and thus increase their privileges on the host.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
History
No history.
Information
Published : 2019-12-30 22:15
Updated : 2026-06-16 23:52
NVD link : CVE-2013-2016
Mitre link : CVE-2013-2016
CVE.ORG link : CVE-2013-2016
JSON object : View
Products Affected
novell
- open_desktop_server
- open_enterprise_server
qemu
- qemu
debian
- debian_linux
CWE
CWE-269
Improper Privilege Management
