CVE Database
/

CVE-2011-2512

Back to search

CVE-2011-2512

Published: Jun 21, 2012

Modified: Aug 6, 2024

PUBLISHED

Description

The virtio_queue_notify in qemu-kvm 0.14.0 and earlier does not properly validate the virtqueue number, which allows guest users to cause a denial of service (guest crash) and possibly execute arbitrary code via a negative number in the Queue Notify field of the Virtio Header, which bypasses a signed comparison.

VendorProductVersions

n/a

n/a

affected
n/a

References

RHSA-2011:0919
vendor-advisory
x_refsource_REDHAT
45170
third-party-advisory
x_refsource_SECUNIA
44648
third-party-advisory
x_refsource_SECUNIA
45301
third-party-advisory
x_refsource_SECUNIA
45158
third-party-advisory
x_refsource_SECUNIA
openSUSE-SU-2011:0803
vendor-advisory
x_refsource_SUSE
74751
vdb-entry
x_refsource_OSVDB
44458
third-party-advisory
x_refsource_SECUNIA
USN-1165-1
vendor-advisory
x_refsource_UBUNTU
DSA-2270
vendor-advisory
x_refsource_DEBIAN
SUSE-SU-2011:0806
vendor-advisory
x_refsource_SUSE

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now