Description
The usb_device_post_load function in hw/usb/bus.c in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via a crafted savevm image, related to a negative setup_len or setup_index value.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2013-4400 | The usb_device_post_load function in hw/usb/bus.c in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via a crafted savevm image, related to a negative setup_len or setup_index value. |
Ubuntu USN |
USN-2342-1 | QEMU vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T16:45:14.804Z
Reserved: 2013-06-12T00:00:00.000Z
Link: CVE-2013-4541
No data.
Status : Modified
Published: 2014-11-04T21:55:24.953
Modified: 2026-05-06T22:30:45.220
Link: CVE-2013-4541
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Ubuntu USN