CVE-2011-2212

Publication date 20 June 2011

Last updated 24 July 2024


Ubuntu priority

Buffer overflow in the virtio subsystem in qemu-kvm 0.14.0 and earlier allows privileged guest users to cause a denial of service (guest crash) or gain privileges via a crafted indirect descriptor related to “virtqueue in and out requests.”

Read the notes from the security team

Status

No maintained releases are affected by this CVE.

Package Ubuntu Release Status
qemu-kvm 11.04 natty
Fixed 0.14.0+noroms-0ubuntu4.3
10.10 maverick
Fixed 0.12.5+noroms-0ubuntu7.8
10.04 LTS lucid
Fixed 0.12.3+noroms-0ubuntu9.12
8.04 LTS hardy Not in release

Notes


jdstrand

be careful, 0.14.1 and Debian do not have the patch

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
qemu-kvm

References

Related Ubuntu Security Notices (USN)

Other references