An user able to alter the savevm data (either on the disk or over the wire during migration) could use this flaw to to corrupt QEMU process memory on the (destination) host, which could potentially result in arbitrary code execution on the host with the privileges of the QEMU process.
References
Link Resource
https://bugzilla.redhat.com/show_bug.cgi?id=1066401 Issue Tracking Patch Third Party Advisory
https://security.netapp.com/advisory/ntap-20210727-0002/ Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: redhat

Published: 2021-05-28T16:58:49

Updated: 2021-07-27T15:06:36

Reserved: 2013-06-12T00:00:00


Link: CVE-2013-4536

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2021-05-28T17:15:07.350

Modified: 2023-03-03T14:44:24.213


Link: CVE-2013-4536

JSON object: View

cve-icon Redhat Information

No data.

CWE