Description The create_pit_timer function in arch/x86/kvm/i8254.c in KVM 83, and possibly other versions, does not properly handle when Programmable Interval Timer (PIT) interrupt requests (IRQs) when a virtual interrupt controller (irqchip) is not available, which allows local users to cause a denial of service (NULL pointer dereference) by starting a timer.
CVSS vector AV:L/AC:L/C:N/I:N/A:C Exploitability: 3.9 | Impact: 6.9 Complexity: Low
Confidentiality: None
Integrity: None
Affected Packages15 packages ▶ Ubuntu linux < 3.11.0-12.19 +1 Show 10 more packages
🔴 Vulnerability Details3 GHSA GHSA-gqh3-j9ff-5g88: The create_pit_timer function in arch/x86/kvm/i8254 ↗ 2022-05-14 ▶ CVEList CVE-2011-4622: The create_pit_timer function in arch/x86/kvm/i8254 ↗ 2012-01-27 ▶ OSV CVE-2011-4622: The create_pit_timer function in arch/x86/kvm/i8254 ↗ 2012-01-27 ▶
📋 Vendor Advisories8 Ubuntu Linux kernel (EC2) vulnerabilities ↗ 2012-03-06 ▶ Ubuntu Linux kernel (Oneiric backport) vulnerabilities ↗ 2012-03-06 ▶ Ubuntu Linux kernel vulnerabilities ↗ 2012-03-06 ▶ Ubuntu Linux kernel (Natty backport) vulnerabilities ↗ 2012-03-06 ▶ Ubuntu Linux kernel (Maverick backport) vulnerabilities ↗ 2012-03-06 ▶ Show 3 more
💬 Community3 Bugzilla CVE-2011-4622 kernel: kvm: pit timer with no irqchip crashes the system [fedora-all] ↗ 2012-01-03 ▶ Bugzilla CVE-2011-4622 kernel: kvm: pit timer with no irqchip crashes the system [fedora-all] ↗ 2011-12-23 ▶ Bugzilla CVE-2011-4622 kernel: kvm: pit timer with no irqchip crashes the system ↗ 2011-12-21 ▶