CVE-2013-4587: Linux Kernel

High severity, CVSS 7.2. EPSS: 0.5% chance of exploitation in the next 30 days.

Array index error in the kvm_vm_ioctl_create_vcpu function in virt/kvm/kvm_main.c in the KVM subsystem in the Linux kernel through 3.12.5 allows local users to gain privileges via a large id value.

Affected products

  • Linux Linux Kernel: before 3.2.54 (fixed in 3.2.54); from 3.3, before 3.4.75 (fixed in 3.4.75); from 3.5, before 3.10.25 (fixed in 3.10.25); from 3.11, before 3.12.6 (fixed in 3.12.6)
  • Opensuse Opensuse: version 11.4 only; version 12.3 only; version 13.1 only

Published 2013-12-14. Last modified 2026-06-16.