CVE-2013-6457: Red Hat Libvirt
Medium severity, CVSS 5.2. EPSS: 0.7% chance of exploitation in the next 30 days.
The libxlDomainGetNumaParameters function in the libxl driver (libxl/libxl_driver.c) in libvirt before 1.2.1 does not properly initialize the nodemap, which allows local users to cause a denial of service (invalid free operation and crash) or possibly execute arbitrary code via an inactive domain to the virsh numatune command.
Affected products
- Red Hat Libvirt: up to and including 1.2.0; version 0.0.1 only; version 0.0.2 only; version 0.0.3 only; version 0.0.4 only; version 0.0.5 only; …
Published 2014-01-24. Last modified 2026-06-17.