CVE-2013-4535
QEMU vulnerability analysis and mitigation

Overview

The CVE-2013-4535 vulnerability affects the virtqueue_map_sg function in hw/virtio/virtio.c in QEMU versions before 1.7.2. This vulnerability was discovered as part of a state loading code audit performed by Michael S. Tsirkin of Red Hat, Anthony Liguori, and Michael Roth (QEMU Stable).

Technical details

The vulnerability exists in the virtqueue_map_sg function where VirtQueueElements are read as buffers. The issue occurs when num_sg is taken from the wire without proper validation, which can force writes to indices beyond VIRTQUEUE_MAX_SIZE. The vulnerability has a CVSS 3.1 Base Score of 8.8 (High) with the vector string CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H (NVD).

Impact

An attacker who can alter the savevm data, either on disk or during migration over the wire, could exploit this vulnerability to corrupt QEMU process memory on the destination host. This corruption could potentially lead to arbitrary code execution with the privileges of the QEMU process (Red Hat Bugzilla).

Mitigation and workarounds

The vulnerability was fixed in QEMU version 1.7.2. Users are advised to upgrade to this version or apply the appropriate security patches. For systems using Red Hat Enterprise Linux, multiple security advisories (RHSA-2014:0743, RHSA-2014:0744) were released with backported patches. After applying the updates, all running virtual machines must be shut down and restarted for the fix to take effect (Red Hat Advisory).

Additional resources


SourceThis report was generated using AI

Related QEMU vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2024-7730HIGH7.8
  • NixOSNixOS
  • qemu
NoYesNov 14, 2024
CVE-2025-11234HIGH7.5
  • Red Hat Enterprise Linux CoreOS (RHCOS)Red Hat Enterprise Linux CoreOS (RHCOS)
  • qemu-accel-tcg-x86
NoYesOct 03, 2025
CVE-2025-12464MEDIUM6.2
  • CBL MarinerCBL Mariner
  • qemu-SLOF
NoYesOct 31, 2025
CVE-2025-54567MEDIUM5.4
  • NixOSNixOS
  • qemu-kvm-tools
NoYesJul 25, 2025
CVE-2025-54566MEDIUM5.4
  • NixOSNixOS
  • qemu-img
NoYesJul 25, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management