CVE-2011-4622
published 2012-01-27CVE-2011-4622: The create_pit_timer function in arch/x86/kvm/i8254.c in KVM 83, and possibly other versions, does not properly handle when Programmable Interval Timer (PIT)…
PriorityP413medium4.9CVSS 2.0
AVLACLAuNCNINAC
EPSS
0.36%
28.5th percentile
The create_pit_timer function in arch/x86/kvm/i8254.c in KVM 83, and possibly other versions, does not properly handle when Programmable Interval Timer (PIT) interrupt requests (IRQs) when a virtual interrupt controller (irqchip) is not available, which allows local users to cause a denial of service (NULL pointer dereference) by starting a timer.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux_kernel | >= 0 < 3.11.0-12.19 | 3.11.0-12.19 |
| linux | linux_kernel | >= 0 < 4.2.0-16.19 | 4.2.0-16.19 |
| redhat | kvm | — | — |
CVSS provenance
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv4.9MEDIUM
vendor_ubuntu5.5MEDIUM
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (EC2) vulnerabilities
vendor_ubuntu·2012-03-06·CVSS 4.6
CVE-2011-4127 [MEDIUM] Linux kernel (EC2) vulnerabilities
Title: Linux kernel (EC2) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Paolo Bonzini discovered a flaw in Linux's handling of the SG_IO ioctl
command. A local user, or user in a VM could exploit this flaw to bypass
restrictions and gain read/write access to all data on the affected block
device. (CVE-2011-4127)
A flaw was found in KVM's Programmable Interval Timer (PIT). When a virtual
interrupt control is not available a local user could use this to cause a
denial of service by starting a timer. (CVE-2011-4622)
A flaw was discovered in the XFS filesystem. If a local user mounts a
specially crafted XFS image it could potential execute arbitrary code on
the system. (CVE-2012-0038)
A flaw was found in the Linux kernel's ext4 file system when mounting a
corr
Ubuntu
Linux kernel (Oneiric backport) vulnerabilities
vendor_ubuntu·2012-03-06·CVSS 5.5
CVE-2011-4097 [MEDIUM] Linux kernel (Oneiric backport) vulnerabilities
Title: Linux kernel (Oneiric backport) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A bug was discovered in the Linux kernel's calculation of OOM (Out of
memory) scores, that would result in the wrong process being killed. A user
could use this to kill the process with the highest OOM score, even if that
process belongs to another user or the system. (CVE-2011-4097)
Paolo Bonzini discovered a flaw in Linux's handling of the SG_IO ioctl
command. A local user, or user in a VM could exploit this flaw to bypass
restrictions and gain read/write access to all data on the affected block
device. (CVE-2011-4127)
A flaw was found in KVM's Programmable Interval Timer (PIT). When a virtual
interrupt control is not available a local user could use this to cause a
denia
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2012-03-06·CVSS 4.6
CVE-2011-4127 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Paolo Bonzini discovered a flaw in Linux's handling of the SG_IO ioctl
command. A local user, or user in a VM could exploit this flaw to bypass
restrictions and gain read/write access to all data on the affected block
device. (CVE-2011-4127)
A flaw was found in KVM's Programmable Interval Timer (PIT). When a virtual
interrupt control is not available a local user could use this to cause a
denial of service by starting a timer. (CVE-2011-4622)
A flaw was discovered in the XFS filesystem. If a local user mounts a
specially crafted XFS image it could potential execute arbitrary code on
the system. (CVE-2012-0038)
A flaw was found in the Linux kernel's ext4 file system when mounting a
corrupt fi
Ubuntu
Linux kernel (Natty backport) vulnerabilities
vendor_ubuntu·2012-03-06·CVSS 5.5
CVE-2011-2498 [MEDIUM] Linux kernel (Natty backport) vulnerabilities
Title: Linux kernel (Natty backport) vulnerabilities
Summary: Several security issues were fixed in the kernel.
The linux kernel did not properly account for PTE pages when deciding which
task to kill in out of memory conditions. A local, unprivileged could
exploit this flaw to cause a denial of service. (CVE-2011-2498)
A flaw was discovered in the TOMOYO LSM's handling of mount system calls.
An unprivileged user could oops the system causing a denial of service.
(CVE-2011-2518)
Han-Wen Nienhuys reported a flaw in the FUSE kernel module. A local user
who can mount a FUSE file system could cause a denial of service.
(CVE-2011-3353)
A bug was discovered in the Linux kernel's calculation of OOM (Out of
memory) scores, that would result in the wrong process being killed. A user
could use
Ubuntu
Linux kernel (Maverick backport) vulnerabilities
vendor_ubuntu·2012-03-06·CVSS 4.7
CVE-2012-0044 [MEDIUM] Linux kernel (Maverick backport) vulnerabilities
Title: Linux kernel (Maverick backport) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Aristide Fattori and Roberto Paleari reported a flaw in the Linux kernel's
handling of IPv4 icmp packets. A remote user could exploit this to cause a
denial of service. (CVE-2011-1927)
A flaw was found in the Linux Ethernet bridge's handling of IGMP (Internet
Group Management Protocol) packets. An unprivileged local user could
exploit this flaw to crash the system. (CVE-2011-0716)
Han-Wen Nienhuys reported a flaw in the FUSE kernel module. A local user
who can mount a FUSE file system could cause a denial of service.
(CVE-2011-3353)
A flaw was discovered in the Linux kernel's AppArmor security interface
when invalid information was written to it. An unprivileged local use
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2012-02-13·CVSS 5.5
CVE-2012-0055 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
A bug was discovered in the Linux kernel's calculation of OOM (Out of
memory) scores, that would result in the wrong process being killed. A user
could use this to kill the process with the highest OOM score, even if that
process belongs to another user or the system. (CVE-2011-4097)
A flaw was found in KVM's Programmable Interval Timer (PIT). When a virtual
interrupt control is not available a local user could use this to cause a
denial of service by starting a timer. (CVE-2011-4622)
A flaw was discovered in the XFS filesystem. If a local user mounts a
specially crafted XFS image it could potential execute arbitrary code on
the system. (CVE-2012-0038)
Andy Whitcroft discovered a that the Ov
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2012-02-13·CVSS 5.5
CVE-2011-3353 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Han-Wen Nienhuys reported a flaw in the FUSE kernel module. A local user
who can mount a FUSE file system could cause a denial of service.
(CVE-2011-3353)
A flaw was found in KVM's Programmable Interval Timer (PIT). When a virtual
interrupt control is not available a local user could use this to cause a
denial of service by starting a timer. (CVE-2011-4622)
A flaw was discovered in the XFS filesystem. If a local user mounts a
specially crafted XFS image it could potential execute arbitrary code on
the system. (CVE-2012-0038)
Chen Haogang discovered an integer overflow that could result in memory
corruption. A local unprivileged user could use this to crash the system.
(CVE-2012-0044)
Instru
Red Hat
kernel: kvm: pit timer with no irqchip crashes the system
vendor_redhat·2011-12-14·CVSS 4.9
CVE-2011-4622 [MEDIUM] kernel: kvm: pit timer with no irqchip crashes the system
kernel: kvm: pit timer with no irqchip crashes the system
The create_pit_timer function in arch/x86/kvm/i8254.c in KVM 83, and possibly other versions, does not properly handle when Programmable Interval Timer (PIT) interrupt requests (IRQs) when a virtual interrupt controller (irqchip) is not available, which allows local users to cause a denial of service (NULL pointer dereference) by starting a timer.
Statement: This issue did not affect the versions of Linux kernel as shipped with Red Hat Enterprise Linux 4 and Red Hat Enterprise MRG as they did not provide support for the KVM subsystem. It has been addressed in Red Hat Enterprise 5 and 6 via https://rhn.redhat.com/errata/RHSA-2012-0051.html and https://rhn.redhat.com/errata/RHSA-2012-0350.html.
Package: kernel (Red Hat Enterprise L
GHSA
GHSA-gqh3-j9ff-5g88: The create_pit_timer function in arch/x86/kvm/i8254
ghsa_unreviewed·2022-05-14
CVE-2011-4622 [MEDIUM] GHSA-gqh3-j9ff-5g88: The create_pit_timer function in arch/x86/kvm/i8254
The create_pit_timer function in arch/x86/kvm/i8254.c in KVM 83, and possibly other versions, does not properly handle when Programmable Interval Timer (PIT) interrupt requests (IRQs) when a virtual interrupt controller (irqchip) is not available, which allows local users to cause a denial of service (NULL pointer dereference) by starting a timer.
OSV
CVE-2011-4622: The create_pit_timer function in arch/x86/kvm/i8254
osv·2012-01-27·CVSS 4.9
CVE-2011-4622 [MEDIUM] CVE-2011-4622: The create_pit_timer function in arch/x86/kvm/i8254
The create_pit_timer function in arch/x86/kvm/i8254.c in KVM 83, and possibly other versions, does not properly handle when Programmable Interval Timer (PIT) interrupt requests (IRQs) when a virtual interrupt controller (irqchip) is not available, which allows local users to cause a denial of service (NULL pointer dereference) by starting a timer. BUG: unable to handle kernel NULL pointer dereference at 0000000000000128 IP: [] kvm_set_irq+0x30/0x170 [kvm] ... Call Trace: [] pit_do_work+0x51/0xd0 [kvm] [] process_one_work+0x111/0x4d0 [] worker_thread+0x152/0x340 [] kthread+0x7e/0x90 [] kernel_thread_helper+0x4/0x10
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-4622 kernel: kvm: pit timer with no irqchip crashes the system [fedora-all]
bugzilla·2012-01-03·CVSS 4.9
CVE-2011-4622 [MEDIUM] CVE-2011-4622 kernel: kvm: pit timer with no irqchip crashes the system [fedora-all]
CVE-2011-4622 kernel: kvm: pit timer with no irqchip crashes the system [fedora-all]
+++ This bug was initially created as a clone of Bug #770102 +++
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update
Bugzilla
CVE-2011-4622 kernel: kvm: pit timer with no irqchip crashes the system [fedora-all]
bugzilla·2011-12-23·CVSS 4.9
CVE-2011-4622 [MEDIUM] CVE-2011-4622 kernel: kvm: pit timer with no irqchip crashes the system [fedora-all]
CVE-2011-4622 kernel: kvm: pit timer with no irqchip crashes the system [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_
Bugzilla
CVE-2011-4622 kernel: kvm: pit timer with no irqchip crashes the system
bugzilla·2011-12-21·CVSS 4.9
CVE-2011-4622 [MEDIUM] CVE-2011-4622 kernel: kvm: pit timer with no irqchip crashes the system
CVE-2011-4622 kernel: kvm: pit timer with no irqchip crashes the system
User space may create the PIT and forgets about setting up the irqchips.
In that case, firing PIT IRQs will crash the host:
BUG: unable to handle kernel NULL pointer dereference at 0000000000000128
IP: [] kvm_set_irq+0x30/0x170 [kvm]
...
Call Trace:
[] pit_do_work+0x51/0xd0 [kvm]
[] process_one_work+0x111/0x4d0
[] worker_thread+0x152/0x340
[] kthread+0x7e/0x90
[] kernel_thread_helper+0x4/0x10
Reference:
http://permalink.gmane.org/gmane.comp.emulators.kvm.devel/83564
Discussion:
Added CVE-2011-4622 as per http://www.openwall.com/lists/oss-security/2011/12/21/7
---
Created kernel tracking bugs for this issue
Affects: fedora-all [bug 770102]
---
kernel-3.1.7-1.fc16 has been pushed to the Fedora 16 stable reposit
http://lists.opensuse.org/opensuse-security-announce/2012-05/msg00013.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-06/msg00005.htmlhttp://permalink.gmane.org/gmane.comp.emulators.kvm.devel/83564http://www.openwall.com/lists/oss-security/2011/12/21/7http://www.redhat.com/support/errata/RHSA-2012-0051.htmlhttp://www.securityfocus.com/bid/51172http://www.securitytracker.com/id?1026559https://bugzilla.redhat.com/show_bug.cgi?id=769721http://lists.opensuse.org/opensuse-security-announce/2012-05/msg00013.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-06/msg00005.htmlhttp://permalink.gmane.org/gmane.comp.emulators.kvm.devel/83564http://www.openwall.com/lists/oss-security/2011/12/21/7http://www.redhat.com/support/errata/RHSA-2012-0051.htmlhttp://www.securityfocus.com/bid/51172http://www.securitytracker.com/id?1026559https://bugzilla.redhat.com/show_bug.cgi?id=769721
2012-01-27
Published