CVE-2012-2119
published 2013-01-22CVE-2012-2119: Buffer overflow in the macvtap device driver in the Linux kernel before 3.4.5, when running in certain configurations, allows privileged KVM guest users to…
PriorityP420medium5.2CVSS 2.0
AVAACMAuSCNINAC
EPSS
0.71%
50.1th percentile
Buffer overflow in the macvtap device driver in the Linux kernel before 3.4.5, when running in certain configurations, allows privileged KVM guest users to cause a denial of service (crash) via a long descriptor with a long vector length.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.2.20-1 (bookworm) | linux 3.2.20-1 (bookworm) |
| linux | linux_kernel | <= 3.4.4 | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 3.2.20-1 | 3.2.20-1 |
| linux | linux_kernel | >= 0 < 3.2.20-1 | 3.2.20-1 |
| linux | linux_kernel | >= 0 < 3.2.20-1 | 3.2.20-1 |
| linux | linux_kernel | >= 0 < 3.2.20-1 | 3.2.20-1 |
CVSS provenance
nvdv2.05.2MEDIUMAV:A/AC:M/Au:S/C:N/I:N/A:C
osv5.2MEDIUM
vendor_debian5.2MEDIUM
vendor_redhat5.2MEDIUM
vendor_ubuntu5.2MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7wpp-8mhw-h7xv: Buffer overflow in the macvtap device driver in the Linux kernel before 3
ghsa_unreviewed·2022-05-17
CVE-2012-2119 [MEDIUM] CWE-119 GHSA-7wpp-8mhw-h7xv: Buffer overflow in the macvtap device driver in the Linux kernel before 3
Buffer overflow in the macvtap device driver in the Linux kernel before 3.4.5, when running in certain configurations, allows privileged KVM guest users to cause a denial of service (crash) via a long descriptor with a long vector length.
OSV
CVE-2012-2119: Buffer overflow in the macvtap device driver in the Linux kernel before 3
osv·2013-01-22·CVSS 5.2
CVE-2012-2119 [MEDIUM] CVE-2012-2119: Buffer overflow in the macvtap device driver in the Linux kernel before 3
Buffer overflow in the macvtap device driver in the Linux kernel before 3.4.5, when running in certain configurations, allows privileged KVM guest users to cause a denial of service (crash) via a long descriptor with a long vector length.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2012-08-10·CVSS 5.2
CVE-2012-2119 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
A flaw was discovered in the Linux kernel's macvtap device driver, which is
used in KVM (Kernel-based Virtual Machine) to create a network bridge
between host and guest. A privleged user in a guest could exploit this flaw
to crash the host, if the vhost_net module is loaded with the
experimental_zcopytx option enabled. (CVE-2012-2119)
An error was discovered in the Linux kernel's network TUN/TAP device
implementation. A local user with access to the TUN/TAP interface (which is
not available to unprivileged users until granted by a root user) could
exploit this flaw to crash the system or potential gain administrative
privileges. (CVE-2012-2136)
A flaw was found in how the Linux kernel's KVM (
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2012-08-10·CVSS 5.2
CVE-2012-2119 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A flaw was discovered in the Linux kernel's macvtap device driver, which is
used in KVM (Kernel-based Virtual Machine) to create a network bridge
between host and guest. A privleged user in a guest could exploit this flaw
to crash the host, if the vhost_net module is loaded with the
experimental_zcopytx option enabled. (CVE-2012-2119)
An error was discovered in the Linux kernel's network TUN/TAP device
implementation. A local user with access to the TUN/TAP interface (which is
not available to unprivileged users until granted by a root user) could
exploit this flaw to crash the system or potential gain administrative
privileges. (CVE-2012-2136)
A flaw was found in how the Linux kernel
Red Hat
kernel: macvtap: zerocopy: vector length is not validated before pinning user pages
vendor_redhat·2012-04-16·CVSS 5.2
CVE-2012-2119 [MEDIUM] kernel: macvtap: zerocopy: vector length is not validated before pinning user pages
kernel: macvtap: zerocopy: vector length is not validated before pinning user pages
Buffer overflow in the macvtap device driver in the Linux kernel before 3.4.5, when running in certain configurations, allows privileged KVM guest users to cause a denial of service (crash) via a long descriptor with a long vector length.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: realtime-kernel (Red Hat Enterprise MRG 2) - Not affected
Debian
CVE-2012-2119: linux - Buffer overflow in the macvtap device driver in the Linux kernel before 3.4.5, w...
vendor_debian·2012·CVSS 5.2
CVE-2012-2119 [MEDIUM] CVE-2012-2119: linux - Buffer overflow in the macvtap device driver in the Linux kernel before 3.4.5, w...
Buffer overflow in the macvtap device driver in the Linux kernel before 3.4.5, when running in certain configurations, allows privileged KVM guest users to cause a denial of service (crash) via a long descriptor with a long vector length.
Scope: local
bookworm: resolved (fixed in 3.2.20-1)
bullseye: resolved (fixed in 3.2.20-1)
forky: resolved (fixed in 3.2.20-1)
sid: resolved (fixed in 3.2.20-1)
trixie: resolved (fixed in 3.2.20-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-2119 kernel: macvtap: zerocopy: vector length is not validated before pinning user pages
bugzilla·2012-04-19·CVSS 5.2
CVE-2012-2119 [MEDIUM] CVE-2012-2119 kernel: macvtap: zerocopy: vector length is not validated before pinning user pages
CVE-2012-2119 kernel: macvtap: zerocopy: vector length is not validated before pinning user pages
Currently we do not validate the vector length before calling get_user_pages_fast(), host stack could be easily overflowed by malicious guest driver who gives us a descriptors with length greater than MAX_SKB_FRAGS.
A privileged guest user could use this flaw to induce stack overflow on the host with attacker non-controlled data (some bits can be guessed, as it will be pointers to kernel memory) but with attacker controlled length.
References:
http://marc.info/?l=linux-netdev&m=133455718001608&w=2
Discussion:
Created kernel tracking bugs for this issue
Affects: fedora-all [bug 814289]
---
Added CVE as per http://www.openwall.com/lists/oss-security/2012/04/19/14
---
kernel-3.3.2-8.fc1
Bugzilla
CVE-2012-2119 kernel: macvtap: zerocopy: vector length is not validated before pinning user pages [fedora-all]
bugzilla·2012-04-19·CVSS 5.2
CVE-2012-2119 [MEDIUM] CVE-2012-2119 kernel: macvtap: zerocopy: vector length is not validated before pinning user pages [fedora-all]
CVE-2012-2119 kernel: macvtap: zerocopy: vector length is not validated before pinning user pages [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproj
http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=814278http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=b92946e2919134ebe2a4083e4302236295ea2a73http://lists.opensuse.org/opensuse-security-announce/2013-06/msg00005.htmlhttp://marc.info/?l=linux-netdev&m=133455718001608&w=2http://rhn.redhat.com/errata/RHSA-2012-0743.htmlhttp://ubuntu.com/usn/usn-1529-1http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.4.5http://www.openwall.com/lists/oss-security/2012/04/19/14https://github.com/torvalds/linux/commit/b92946e2919134ebe2a4083e4302236295ea2a73https://oss.oracle.com/git/?p=redpatch.git%3Ba=commit%3Bh=4aae94d1c7b32316911c86176c0ed4f8ed62da73http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=814278http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=b92946e2919134ebe2a4083e4302236295ea2a73http://lists.opensuse.org/opensuse-security-announce/2013-06/msg00005.htmlhttp://marc.info/?l=linux-netdev&m=133455718001608&w=2http://rhn.redhat.com/errata/RHSA-2012-0743.htmlhttp://ubuntu.com/usn/usn-1529-1http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.4.5http://www.openwall.com/lists/oss-security/2012/04/19/14https://github.com/torvalds/linux/commit/b92946e2919134ebe2a4083e4302236295ea2a73https://oss.oracle.com/git/?p=redpatch.git%3Ba=commit%3Bh=4aae94d1c7b32316911c86176c0ed4f8ed62da73
2013-01-22
Published