CVE-2011-1750
Publication date 29 May 2011
Last updated 24 July 2024
Ubuntu priority
Multiple heap-based buffer overflows in the virtio-blk driver (hw/virtio-blk.c) in qemu-kvm 0.14.0 allow local guest users to cause a denial of service (guest crash) and possibly gain privileges via a (1) write request to the virtio_blk_handle_write function or (2) read request to the virtio_blk_handle_read function that is not properly aligned.
Status
Package | Ubuntu Release | Status |
---|---|---|
qemu-kvm | ||
Notes
jdstrand
adding apparmor tag since qemu-kvm is typically used with libvirt on Ubuntu, and is therefore confined by AppArmor
Patch details
Package | Patch details |
---|---|
qemu-kvm |
References
Related Ubuntu Security Notices (USN)
- USN-1145-1
- QEMU vulnerabilities
- 9 June 2011