CVE-2012-2121
The KVM implementation in the Linux kernel before 3.3.4 does not properly manage the relationships between memory slots and the iommu, which allows guest OS users to cause a denial of service (memory leak and host OS crash) by leveraging administrative…
Does this matter?
Lower severity and a low EPSS score (0.41%). Track it; it rarely justifies an emergency change on its own.
Description
The KVM implementation in the Linux kernel before 3.3.4 does not properly manage the relationships between memory slots and the iommu, which allows guest OS users to cause a denial of service (memory leak and host OS crash) by leveraging administrative access to the guest OS to conduct hotunplug and hotplug operations on devices.
- CVSS 2.0
- 4.9 MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
- EPSS
- 0.41% probability · 35th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- linux/linux kernel
- Source
- secalert@redhat.com
References
- http://rhn.redhat.com/errata/RHSA-2012-0676.html
- http://rhn.redhat.com/errata/RHSA-2012-0743.html
- http://secunia.com/advisories/50732
- http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.3.4
- http://www.openwall.com/lists/oss-security/2012/04/19/16
- http://www.securitytracker.com/id?1027083
- http://www.ubuntu.com/usn/USN-1577-1
- http://www.ubuntu.com/usn/USN-2036-1
- http://www.ubuntu.com/usn/USN-2037-1
- https://bugzilla.redhat.com/show_bug.cgi?id=814149
- https://github.com/torvalds/linux/commit/09ca8e1173bcb12e2a449698c9ae3b86a8a10195
- http://rhn.redhat.com/errata/RHSA-2012-0676.html
- http://rhn.redhat.com/errata/RHSA-2012-0743.html
- http://secunia.com/advisories/50732
- http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.3.4
- http://www.openwall.com/lists/oss-security/2012/04/19/16
- http://www.securitytracker.com/id?1027083
- http://www.ubuntu.com/usn/USN-1577-1
- http://www.ubuntu.com/usn/USN-2036-1
- http://www.ubuntu.com/usn/USN-2037-1
- https://bugzilla.redhat.com/show_bug.cgi?id=814149
- https://github.com/torvalds/linux/commit/09ca8e1173bcb12e2a449698c9ae3b86a8a10195
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.