CVE-2013-2124

Exp

Double free vulnerability in inspect-fs.c in LibguestFS 1.20.x before 1.20.7, 1.21.x, 1.22.0, and 1.23.0 allows remote attackers to cause a denial of service (crash) via empty guest files.

Published: 2014-05-27 Last update: 2026-05-06 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2013-2124 is rated Exploit Available (58.1/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 0.91%). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Public exploit references (Exploit-DB) for CVE-2013-2124

EDB-ID Source Kind Published Link
nvd_ref exploit_tag Exploit-DB ↗

Exploit prediction scoring system (EPSS) score for CVE-2013-2124

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2025-08-23 1.20% 0.91% -0.30%
2 2025-03-30 1.62% 1.20% -0.41%
3 2025-03-29 1.62%

Full EPSS history (10 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2013-2124

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
4.3 2.0 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:M)
Exploitation needs some favorable conditions, but not exceptional ones.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:N)
No confidentiality impact.
Integrity impact (I:N)
No integrity impact.
Availability impact (A:P)
Partial availability impact.
8.6 2.9 [email protected]

Weakness enumeration for CVE-2013-2124

OS Trackers for CVE-2013-2124

vendor priority summary link
debian not yet assigned CVE-2013-2124 not yet assigned priority: Debian including 1 source packages (libguestfs), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. https://security-tracker.debian.org/tracker/CVE-2013-2124
redhat medium https://access.redhat.com/security/cve/CVE-2013-2124
suse medium CVE-2013-2124 severity moderate: SUSE including 101 source package names (guestfs-data-1.20.12-0.18.70, guestfs-data-1.20.4-0.14.9, …), 143 product×package rows across 27 product lines (SUSE Linux Enterprise High Performance Computing 12 SP5, SUSE Linux Enterprise Module for Development Tools 15, … (27 product lines)): Fixed 143. https://www.suse.com/security/cve/CVE-2013-2124/
ubuntu medium CVE-2013-2124 medium priority: Ubuntu including 1 source packages (libguestfs), 19 status rows across 19 suites (artful, bionic, cosmic, disco, eoan, focal, lucid, precise, quantal, raring, saucy, trusty, upstream, utopic, vivid, wily, xenial, yakkety, zesty): ignored 13, not-affected 3, DNE 2, released 1. https://ubuntu.com/security/CVE-2013-2124

NVD evaluator notes for CVE-2013-2124

Comment: Per: http://cwe.mitre.org/data/definitions/415.html "CWE-415: Double Free"

Affected software / configurations for CVE-2013-2124

Vendor Product Version Raw CPE
libguestfs libguestfs 1.20.0 cpe:2.3:a:libguestfs:libguestfs:1.20.0:*:*:*:*:*:*:*
libguestfs libguestfs 1.20.1 cpe:2.3:a:libguestfs:libguestfs:1.20.1:*:*:*:*:*:*:*
libguestfs libguestfs 1.20.2 cpe:2.3:a:libguestfs:libguestfs:1.20.2:*:*:*:*:*:*:*
libguestfs libguestfs 1.20.3 cpe:2.3:a:libguestfs:libguestfs:1.20.3:*:*:*:*:*:*:*
libguestfs libguestfs 1.20.4 cpe:2.3:a:libguestfs:libguestfs:1.20.4:*:*:*:*:*:*:*
libguestfs libguestfs 1.20.5 cpe:2.3:a:libguestfs:libguestfs:1.20.5:*:*:*:*:*:*:*
libguestfs libguestfs 1.20.6 cpe:2.3:a:libguestfs:libguestfs:1.20.6:*:*:*:*:*:*:*
libguestfs libguestfs 1.21.1 cpe:2.3:a:libguestfs:libguestfs:1.21.1:*:*:*:*:*:*:*
libguestfs libguestfs 1.21.2 cpe:2.3:a:libguestfs:libguestfs:1.21.2:*:*:*:*:*:*:*
libguestfs libguestfs 1.21.3 cpe:2.3:a:libguestfs:libguestfs:1.21.3:*:*:*:*:*:*:*
libguestfs libguestfs 1.21.4 cpe:2.3:a:libguestfs:libguestfs:1.21.4:*:*:*:*:*:*:*
libguestfs libguestfs 1.21.5 cpe:2.3:a:libguestfs:libguestfs:1.21.5:*:*:*:*:*:*:*
libguestfs libguestfs 1.21.6 cpe:2.3:a:libguestfs:libguestfs:1.21.6:*:*:*:*:*:*:*
libguestfs libguestfs 1.21.7 cpe:2.3:a:libguestfs:libguestfs:1.21.7:*:*:*:*:*:*:*
libguestfs libguestfs 1.21.8 cpe:2.3:a:libguestfs:libguestfs:1.21.8:*:*:*:*:*:*:*
libguestfs libguestfs 1.21.9 cpe:2.3:a:libguestfs:libguestfs:1.21.9:*:*:*:*:*:*:*
libguestfs libguestfs 1.21.10 cpe:2.3:a:libguestfs:libguestfs:1.21.10:*:*:*:*:*:*:*
libguestfs libguestfs 1.21.11 cpe:2.3:a:libguestfs:libguestfs:1.21.11:*:*:*:*:*:*:*
libguestfs libguestfs 1.21.12 cpe:2.3:a:libguestfs:libguestfs:1.21.12:*:*:*:*:*:*:*
libguestfs libguestfs 1.21.13 cpe:2.3:a:libguestfs:libguestfs:1.21.13:*:*:*:*:*:*:*
libguestfs libguestfs 1.21.14 cpe:2.3:a:libguestfs:libguestfs:1.21.14:*:*:*:*:*:*:*
libguestfs libguestfs 1.21.15 cpe:2.3:a:libguestfs:libguestfs:1.21.15:*:*:*:*:*:*:*
libguestfs libguestfs 1.21.16 cpe:2.3:a:libguestfs:libguestfs:1.21.16:*:*:*:*:*:*:*
libguestfs libguestfs 1.21.17 cpe:2.3:a:libguestfs:libguestfs:1.21.17:*:*:*:*:*:*:*
libguestfs libguestfs 1.21.18 cpe:2.3:a:libguestfs:libguestfs:1.21.18:*:*:*:*:*:*:*
libguestfs libguestfs 1.21.19 cpe:2.3:a:libguestfs:libguestfs:1.21.19:*:*:*:*:*:*:*
libguestfs libguestfs 1.21.20 cpe:2.3:a:libguestfs:libguestfs:1.21.20:*:*:*:*:*:*:*
libguestfs libguestfs 1.21.21 cpe:2.3:a:libguestfs:libguestfs:1.21.21:*:*:*:*:*:*:*
libguestfs libguestfs 1.21.22 cpe:2.3:a:libguestfs:libguestfs:1.21.22:*:*:*:*:*:*:*
libguestfs libguestfs 1.21.23 cpe:2.3:a:libguestfs:libguestfs:1.21.23:*:*:*:*:*:*:*
libguestfs libguestfs 1.21.24 cpe:2.3:a:libguestfs:libguestfs:1.21.24:*:*:*:*:*:*:*
libguestfs libguestfs 1.21.25 cpe:2.3:a:libguestfs:libguestfs:1.21.25:*:*:*:*:*:*:*
libguestfs libguestfs 1.21.26 cpe:2.3:a:libguestfs:libguestfs:1.21.26:*:*:*:*:*:*:*
libguestfs libguestfs 1.21.27 cpe:2.3:a:libguestfs:libguestfs:1.21.27:*:*:*:*:*:*:*
libguestfs libguestfs 1.21.28 cpe:2.3:a:libguestfs:libguestfs:1.21.28:*:*:*:*:*:*:*
libguestfs libguestfs 1.21.29 cpe:2.3:a:libguestfs:libguestfs:1.21.29:*:*:*:*:*:*:*
libguestfs libguestfs 1.21.30 cpe:2.3:a:libguestfs:libguestfs:1.21.30:*:*:*:*:*:*:*
libguestfs libguestfs 1.21.31 cpe:2.3:a:libguestfs:libguestfs:1.21.31:*:*:*:*:*:*:*
libguestfs libguestfs 1.21.32 cpe:2.3:a:libguestfs:libguestfs:1.21.32:*:*:*:*:*:*:*
libguestfs libguestfs 1.21.33 cpe:2.3:a:libguestfs:libguestfs:1.21.33:*:*:*:*:*:*:*
libguestfs libguestfs 1.21.34 cpe:2.3:a:libguestfs:libguestfs:1.21.34:*:*:*:*:*:*:*
libguestfs libguestfs 1.21.35 cpe:2.3:a:libguestfs:libguestfs:1.21.35:*:*:*:*:*:*:*
libguestfs libguestfs 1.21.36 cpe:2.3:a:libguestfs:libguestfs:1.21.36:*:*:*:*:*:*:*
libguestfs libguestfs 1.21.37 cpe:2.3:a:libguestfs:libguestfs:1.21.37:*:*:*:*:*:*:*
libguestfs libguestfs 1.21.38 cpe:2.3:a:libguestfs:libguestfs:1.21.38:*:*:*:*:*:*:*
libguestfs libguestfs 1.21.39 cpe:2.3:a:libguestfs:libguestfs:1.21.39:*:*:*:*:*:*:*
libguestfs libguestfs 1.21.40 cpe:2.3:a:libguestfs:libguestfs:1.21.40:*:*:*:*:*:*:*
libguestfs libguestfs 1.22.0 cpe:2.3:a:libguestfs:libguestfs:1.22.0:*:*:*:*:*:*:*
libguestfs libguestfs 1.23.0 cpe:2.3:a:libguestfs:libguestfs:1.23.0:*:*:*:*:*:*:*

References for CVE-2013-2124

cvelogic Threat Intelligence