CVE-2012-2137

CVSS v2.0 6.9 (Medium)
69% Progress
EPSS 0.04 % (11th)
0.04% Progress
Affected Products 2
Advisories 10

Buffer overflow in virt/kvm/irq_comm.c in the KVM subsystem in the Linux kernel before 3.2.24 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to Message Signaled Interrupts (MSI), irq routing entries, and an incorrect check by the setup_routing_entry function before invoking the kvm_set_irq function.

Weaknesses
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer
CVE Status
PUBLISHED
CNA
Red Hat, Inc.
Published Date
2013-01-22 23:55:02
(11 years ago)
Updated Date
2023-08-11 18:44:45
(13 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Linux Kernel from 2.6.33 version and prior 3.0.72 version cpe:2.3:o:linux:linux_kernel >= 2.6.33 < 3.0.72
  Linux Kernel from 3.1 version and prior 3.2.24 version cpe:2.3:o:linux:linux_kernel >= 3.1 < 3.2.24
  Linux Kernel from 3.3 version and prior 3.4.81 version cpe:2.3:o:linux:linux_kernel >= 3.3 < 3.4.81

Configuration #2

    CPE23 From Up To
  Canonical Ubuntu Linux 10.04 cpe:2.3:o:canonical:ubuntu_linux:10.04:*:*:*:-
  Canonical Ubuntu Linux 11.10 cpe:2.3:o:canonical:ubuntu_linux:11.10
  Canonical Ubuntu Linux 12.04 cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:-
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...