CVE-2012-2137
published 2013-01-22CVE-2012-2137: Buffer overflow in virt/kvm/irq_comm.c in the KVM subsystem in the Linux kernel before 3.2.24 allows local users to cause a denial of service (crash) and…
PriorityP426medium6.9CVSS 2.0
AVLACMAuNCCICAC
EPSS
0.52%
41.4th percentile
Buffer overflow in virt/kvm/irq_comm.c in the KVM subsystem in the Linux kernel before 3.2.24 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to Message Signaled Interrupts (MSI), irq routing entries, and an incorrect check by the setup_routing_entry function before invoking the kvm_set_irq function.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | linux | < linux 3.2.20-1 (bookworm) | linux 3.2.20-1 (bookworm) |
| linux | linux_kernel | >= 0 < 3.2.20-1 | 3.2.20-1 |
| linux | linux_kernel | >= 0 < 3.2.20-1 | 3.2.20-1 |
| linux | linux_kernel | >= 0 < 3.2.20-1 | 3.2.20-1 |
| linux | linux_kernel | >= 0 < 3.2.20-1 | 3.2.20-1 |
| linux | linux_kernel | >= 2.6.33 < 3.0.72 | 3.0.72 |
| linux | linux_kernel | >= 3.1 < 3.2.24 | 3.2.24 |
| linux | linux_kernel | >= 3.3 < 3.4.81 | 3.4.81 |
CVSS provenance
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv6.9MEDIUM
vendor_debian6.9MEDIUM
vendor_redhat6.9MEDIUM
vendor_ubuntu6.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (OMAP4) vulnerability
vendor_ubuntu·2012-10-12·CVSS 6.9
CVE-2012-2137 [MEDIUM] Linux kernel (OMAP4) vulnerability
Title: Linux kernel (OMAP4) vulnerability
Summary: The system could be made to crash under certain conditions.
A flaw was found in how the Linux kernel's KVM (Kernel-based Virtual
Machine) subsystem handled MSI (Message Signaled Interrupts). A local
unprivileged user could exploit this flaw to cause a denial of service or
potentially elevate privileges. (CVE-2012-2137)
Mathias Krause discover an error in Linux kernel's Datagram Congestion
Control Protocol (DCCP) Congestion Control Identifier (CCID) use. A local
attack could exploit this flaw to cause a denial of service (crash) and
potentially escalate privileges if the user can mmap page 0.
(CVE-2013-1827)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2012-10-11·CVSS 6.9
CVE-2012-2137 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
A flaw was found in how the Linux kernel's KVM (Kernel-based Virtual
Machine) subsystem handled MSI (Message Signaled Interrupts). A local
unprivileged user could exploit this flaw to cause a denial of service or
potentially elevate privileges. (CVE-2012-2137)
A flaw was found in how the Linux kernel passed the replacement session
keyring to a child process. An unprivileged local user could exploit this
flaw to cause a denial of service (panic). (CVE-2012-2745)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you t
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2012-10-11·CVSS 5.0
CVE-2012-2127 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Vadim Ponomarev discovered a flaw in the Linux kernel causing a reference
leak when PID namespaces are used. A remote attacker could exploit this
flaw causing a denial of service. (CVE-2012-2127)
A flaw was found in how the Linux kernel's KVM (Kernel-based Virtual
Machine) subsystem handled MSI (Message Signaled Interrupts). A local
unprivileged user could exploit this flaw to cause a denial of service or
potentially elevate privileges. (CVE-2012-2137)
Mathias Krause discover an error in Linux kernel's Datagram Congestion
Control Protocol (DCCP) Congestion Control Identifier (CCID) use. A local
attack could exploit this flaw to cause a denial of service (crash) and
potentially escalate privil
Ubuntu
Linux kernel (Oneiric backport) vulnerabilities
vendor_ubuntu·2012-10-03·CVSS 5.0
CVE-2012-2127 [MEDIUM] Linux kernel (Oneiric backport) vulnerabilities
Title: Linux kernel (Oneiric backport) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Vadim Ponomarev discovered a flaw in the Linux kernel causing a reference
leak when PID namespaces are used. A remote attacker could exploit this
flaw causing a denial of service. (CVE-2012-2127)
A flaw was found in how the Linux kernel's KVM (Kernel-based Virtual
Machine) subsystem handled MSI (Message Signaled Interrupts). A local
unprivileged user could exploit this flaw to cause a denial of service or
potentially elevate privileges. (CVE-2012-2137)
Mathias Krause discover an error in Linux kernel's Datagram Congestion
Control Protocol (DCCP) Congestion Control Identifier (CCID) use. A local
attack could exploit this flaw to cause a denial of service (crash) and
potentia
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2012-08-10·CVSS 5.2
CVE-2012-2119 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
A flaw was discovered in the Linux kernel's macvtap device driver, which is
used in KVM (Kernel-based Virtual Machine) to create a network bridge
between host and guest. A privleged user in a guest could exploit this flaw
to crash the host, if the vhost_net module is loaded with the
experimental_zcopytx option enabled. (CVE-2012-2119)
An error was discovered in the Linux kernel's network TUN/TAP device
implementation. A local user with access to the TUN/TAP interface (which is
not available to unprivileged users until granted by a root user) could
exploit this flaw to crash the system or potential gain administrative
privileges. (CVE-2012-2136)
A flaw was found in how the Linux kernel's KVM (
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2012-08-10·CVSS 5.2
CVE-2012-2119 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A flaw was discovered in the Linux kernel's macvtap device driver, which is
used in KVM (Kernel-based Virtual Machine) to create a network bridge
between host and guest. A privleged user in a guest could exploit this flaw
to crash the host, if the vhost_net module is loaded with the
experimental_zcopytx option enabled. (CVE-2012-2119)
An error was discovered in the Linux kernel's network TUN/TAP device
implementation. A local user with access to the TUN/TAP interface (which is
not available to unprivileged users until granted by a root user) could
exploit this flaw to crash the system or potential gain administrative
privileges. (CVE-2012-2136)
A flaw was found in how the Linux kernel
Red Hat
kernel: kvm: buffer overflow in kvm_set_irq()
vendor_redhat·2012-06-05·CVSS 6.9
CVE-2012-2137 [MEDIUM] kernel: kvm: buffer overflow in kvm_set_irq()
kernel: kvm: buffer overflow in kvm_set_irq()
Buffer overflow in virt/kvm/irq_comm.c in the KVM subsystem in the Linux kernel before 3.2.24 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to Message Signaled Interrupts (MSI), irq routing entries, and an incorrect check by the setup_routing_entry function before invoking the kvm_set_irq function.
Statement: This issue did not affect the versions of the Linux kernel as shipped with Red Hat Enterprise Linux 5 and Red Hat Enterprise MRG. This issue was addressed in Red Hat Enterprise Linux 6 via RHSA-2012:0743 https://rhn.redhat.com/errata/RHSA-2012-0743.html
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: realtime-kernel (Red Hat Enterprise MRG 2) - Not a
Debian
CVE-2012-2137: linux - Buffer overflow in virt/kvm/irq_comm.c in the KVM subsystem in the Linux kernel ...
vendor_debian·2012·CVSS 6.9
CVE-2012-2137 [MEDIUM] CVE-2012-2137: linux - Buffer overflow in virt/kvm/irq_comm.c in the KVM subsystem in the Linux kernel ...
Buffer overflow in virt/kvm/irq_comm.c in the KVM subsystem in the Linux kernel before 3.2.24 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to Message Signaled Interrupts (MSI), irq routing entries, and an incorrect check by the setup_routing_entry function before invoking the kvm_set_irq function.
Scope: local
bookworm: resolved (fixed in 3.2.20-1)
bullseye: resolved (fixed in 3.2.20-1)
forky: resolved (fixed in 3.2.20-1)
sid: resolved (fixed in 3.2.20-1)
trixie: resolved (fixed in 3.2.20-1)
GHSA
GHSA-v5cq-57h8-c596: Buffer overflow in virt/kvm/irq_comm
ghsa_unreviewed·2022-05-17
CVE-2012-2137 [MEDIUM] CWE-119 GHSA-v5cq-57h8-c596: Buffer overflow in virt/kvm/irq_comm
Buffer overflow in virt/kvm/irq_comm.c in the KVM subsystem in the Linux kernel before 3.2.24 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to Message Signaled Interrupts (MSI), irq routing entries, and an incorrect check by the setup_routing_entry function before invoking the kvm_set_irq function.
OSV
CVE-2012-2137: Buffer overflow in virt/kvm/irq_comm
osv·2013-01-22·CVSS 6.9
CVE-2012-2137 [MEDIUM] CVE-2012-2137: Buffer overflow in virt/kvm/irq_comm
Buffer overflow in virt/kvm/irq_comm.c in the KVM subsystem in the Linux kernel before 3.2.24 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to Message Signaled Interrupts (MSI), irq routing entries, and an incorrect check by the setup_routing_entry function before invoking the kvm_set_irq function.
No detection rules found.
No public exploits indexed.
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commitdiff%3Bh=f2ebd422f71cda9c791f76f85d2ca102ae34a1edhttp://lists.opensuse.org/opensuse-security-announce/2013-06/msg00005.htmlhttp://marc.info/?l=bugtraq&m=139447903326211&w=2http://rhn.redhat.com/errata/RHSA-2012-0743.htmlhttp://secunia.com/advisories/50952http://secunia.com/advisories/50961http://ubuntu.5.n6.nabble.com/PATCH-Oneiric-CVE-2012-2137-KVM-Fix-buffer-overflow-in-kvm-set-irq-td4990566.htmlhttp://ubuntu.com/usn/usn-1529-1http://ubuntu.com/usn/usn-1607-1http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.2.24http://www.securityfocus.com/bid/54063http://www.ubuntu.com/usn/USN-1594-1http://www.ubuntu.com/usn/USN-1606-1http://www.ubuntu.com/usn/USN-1609-1https://bugzilla.redhat.com/show_bug.cgi?id=816151http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commitdiff%3Bh=f2ebd422f71cda9c791f76f85d2ca102ae34a1edhttp://lists.opensuse.org/opensuse-security-announce/2013-06/msg00005.htmlhttp://marc.info/?l=bugtraq&m=139447903326211&w=2http://rhn.redhat.com/errata/RHSA-2012-0743.htmlhttp://secunia.com/advisories/50952http://secunia.com/advisories/50961http://ubuntu.5.n6.nabble.com/PATCH-Oneiric-CVE-2012-2137-KVM-Fix-buffer-overflow-in-kvm-set-irq-td4990566.htmlhttp://ubuntu.com/usn/usn-1529-1http://ubuntu.com/usn/usn-1607-1http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.2.24http://www.securityfocus.com/bid/54063http://www.ubuntu.com/usn/USN-1594-1http://www.ubuntu.com/usn/USN-1606-1http://www.ubuntu.com/usn/USN-1609-1https://bugzilla.redhat.com/show_bug.cgi?id=816151
2013-01-22
Published