PT-2011-5234 · Linux+3 · Kvm+4

Kurt Seifried

+1

·

Published

1970-01-01

·

Updated

2017-12-29

·

CVE-2011-4622

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions openSUSE (affected versions not specified) KVM version 83
Description The issue is related to multiple vulnerabilities in various packages of the openSUSE operating system and a vulnerability in the KVM hypervisor. These vulnerabilities can lead to a denial of service (NULL pointer dereference) and potentially allow local users to cause a disruption in the availability of protected information. The vulnerabilities can be exploited remotely. In the case of KVM, the create pit timer function does not properly handle Programmable Interval Timer (PIT) interrupt requests when a virtual interrupt controller is not available.
Recommendations For openSUSE, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For KVM version 83, consider disabling the create pit timer function as a temporary workaround until a patch is available. Restrict access to the kvm set irq function to minimize the risk of exploitation. Avoid using the pit do work function in the affected KVM version until the issue is resolved.

Exploit

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-05303
BDU:2015-05304
BDU:2015-05305
BDU:2015-05306
BDU:2015-05307
BDU:2015-05308
BDU:2015-05309
BDU:2015-05310
BDU:2015-05311
BDU:2015-05312
BDU:2015-05313
BDU:2015-05314
BDU:2015-05315
CESA-2012_0350
CVE-2011-4622
DSA-2389-1
OPENSUSE-SU-2013_0925-1
RHSA-2012:0051
RHSA-2012:0350
RHSA-2012_0051
RHSA-2012_0350
USN-1361-1
USN-1362-1
USN-1363-1
USN-1384-1
USN-1386-1
USN-1387-1
USN-1388-1
USN-1389-1

Affected Products

Centos
Kvm
Red Hat
Suse
Opensuse