CVE-2013-4536: Qemu
High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.
An user able to alter the savevm data (either on the disk or over the wire during migration) could use this flaw to to corrupt QEMU process memory on the (destination) host, which could potentially result in arbitrary code execution on the host with the privileges of the QEMU process.
Affected products
- Qemu Qemu: before 1.5.3 (fixed in 1.5.3)
Published 2021-05-28. Last modified 2026-06-16.