CVE-2013-2016: Debian Linux

High severity, CVSS 7.8. EPSS: 0.5% chance of exploitation in the next 30 days.

A flaw was found in the way qemu v1.3.0 and later (virtio-rng) validates addresses when guest accesses the config space of a virtio device. If the virtio device has zero/small sized config space, such as virtio-rng, a privileged guest user could use this flaw to access the matching host's qemu address space and thus increase their privileges on the host.

Affected products

  • Debian Debian Linux: version 8.0 only; version 9.0 only; version 10.0 only
  • Novell Open Desktop Server: version 11.0 only
  • Novell Open Enterprise Server: version 11.0 only
  • Qemu Qemu: from 1.3.0, up to and including 1.4.2; version 1.5.0 only

Published 2019-12-30. Last modified 2026-06-16.