PT-2011-5234 · Linux+3 · Kvm+4
Kurt Seifried
+1
·
Published
1970-01-01
·
Updated
2017-12-29
·
CVE-2011-4622
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
openSUSE (affected versions not specified)
KVM version 83
Description
The issue is related to multiple vulnerabilities in various packages of the openSUSE operating system and a vulnerability in the KVM hypervisor. These vulnerabilities can lead to a denial of service (NULL pointer dereference) and potentially allow local users to cause a disruption in the availability of protected information. The vulnerabilities can be exploited remotely. In the case of KVM, the
create pit timer function does not properly handle Programmable Interval Timer (PIT) interrupt requests when a virtual interrupt controller is not available.Recommendations
For openSUSE, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
For KVM version 83, consider disabling the
create pit timer function as a temporary workaround until a patch is available. Restrict access to the kvm set irq function to minimize the risk of exploitation. Avoid using the pit do work function in the affected KVM version until the issue is resolved.Exploit
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Centos
Kvm
Red Hat
Suse
Opensuse