← Back to CVE List

CVE-2013-2016

Published: 2019-12-30T22:15Z
Last Modified: 2024-11-21T01:50Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
A flaw was found in the way qemu v1.3.0 and later (virtio-rng) validates addresses when guest accesses the config space of a virtio device. If the virtio device has zero/small sized config space, such as virtio-rng, a privileged guest user could use this flaw to access the matching host's qemu address space and thus increase their privileges on the host. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt