Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2011-2512

Published: 5 July 2011

The virtio_queue_notify in qemu-kvm 0.14.0 and earlier does not properly validate the virtqueue number, which allows guest users to cause a denial of service (guest crash) and possibly execute arbitrary code via a negative number in the Queue Notify field of the Virtio Header, which bypasses a signed comparison.

Priority

Medium

Status

Package Release Status
qemu-kvm
Launchpad, Ubuntu, Debian
hardy Does not exist

lucid
Released (0.12.3+noroms-0ubuntu9.12)
maverick
Released (0.12.5+noroms-0ubuntu7.8)
natty
Released (0.14.0+noroms-0ubuntu4.3)
upstream
Released (0.14.1+dfsg-2)
Patches:
other: http://patchwork.ozlabs.org/patch/94604/
vendor: https://rhn.redhat.com/errata/RHSA-2011-0919.html
vendor: http://www.debian.org/security/2011/dsa-2270
This vulnerability is mitigated in part by an AppArmor profile.