CVE-2012-2693
published 2012-06-17CVE-2012-2693: libvirt, possibly before 0.9.12, does not properly assign USB devices to virtual machines when multiple devices have the same vendor and product ID, which…
PriorityP411low3.7CVSS 2.0
AVLACHAuNCPIPAP
EPSS
0.33%
25.3th percentile
libvirt, possibly before 0.9.12, does not properly assign USB devices to virtual machines when multiple devices have the same vendor and product ID, which might cause the wrong device to be associated with a guest and might allow local users to access unintended USB devices.
Affected
72 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libvirt | < libvirt 0.9.12-1 (bookworm) | libvirt 0.9.12-1 (bookworm) |
| redhat | libvirt | <= 0.9.11 | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
CVSS provenance
nvdv2.03.7LOWAV:L/AC:H/Au:N/C:P/I:P/A:P
osv3.7LOW
vendor_debian3.7LOW
vendor_redhat3.7LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
libvirt: address bus= device= when identicle vendor ID/product IDs usb devices attached are ignored
vendor_redhat·2012-04-28·CVSS 3.7
CVE-2012-2693 [LOW] libvirt: address bus= device= when identicle vendor ID/product IDs usb devices attached are ignored
libvirt: address bus= device= when identicle vendor ID/product IDs usb devices attached are ignored
libvirt, possibly before 0.9.12, does not properly assign USB devices to virtual machines when multiple devices have the same vendor and product ID, which might cause the wrong device to be associated with a guest and might allow local users to access unintended USB devices.
Package: libvirt (Red Hat Enterprise Linux 5) - Affected
Debian
CVE-2012-2693: libvirt - libvirt, possibly before 0.9.12, does not properly assign USB devices to virtual...
vendor_debian·2012·CVSS 3.7
CVE-2012-2693 [LOW] CVE-2012-2693: libvirt - libvirt, possibly before 0.9.12, does not properly assign USB devices to virtual...
libvirt, possibly before 0.9.12, does not properly assign USB devices to virtual machines when multiple devices have the same vendor and product ID, which might cause the wrong device to be associated with a guest and might allow local users to access unintended USB devices.
Scope: local
bookworm: resolved (fixed in 0.9.12-1)
bullseye: resolved (fixed in 0.9.12-1)
forky: resolved (fixed in 0.9.12-1)
sid: resolved (fixed in 0.9.12-1)
trixie: resolved (fixed in 0.9.12-1)
GHSA
GHSA-p575-v2mx-34m6: libvirt, possibly before 0
ghsa_unreviewed·2022-05-17
CVE-2012-2693 [LOW] GHSA-p575-v2mx-34m6: libvirt, possibly before 0
libvirt, possibly before 0.9.12, does not properly assign USB devices to virtual machines when multiple devices have the same vendor and product ID, which might cause the wrong device to be associated with a guest and might allow local users to access unintended USB devices.
OSV
CVE-2012-2693: libvirt, possibly before 0
osv·2012-06-17·CVSS 3.7
CVE-2012-2693 [LOW] CVE-2012-2693: libvirt, possibly before 0
libvirt, possibly before 0.9.12, does not properly assign USB devices to virtual machines when multiple devices have the same vendor and product ID, which might cause the wrong device to be associated with a guest and might allow local users to access unintended USB devices.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-2693 libvirt: address bus= device= when identicle vendor ID/product IDs usb devices attached are ignored
bugzilla·2012-06-12·CVSS 3.7
CVE-2012-2693 [LOW] CVE-2012-2693 libvirt: address bus= device= when identicle vendor ID/product IDs usb devices attached are ignored
CVE-2012-2693 libvirt: address bus= device= when identicle vendor ID/product IDs usb devices attached are ignored
libvirt ignores address bus= device= when identicle vendor ID/product IDs usb devices attached with either virsh or virt-manager.
As a consequence, wrong USB device can be assigned to the wrong guest.
References and proposed upstream patch:
https://www.redhat.com/archives/libvir-list/2012-April/msg01494.html
Discussion:
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Via RHSA-2012:0748 https://rhn.redhat.com/errata/RHSA-2012-0748.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2013:0127 https://rhn.redhat.com/errata/RHSA-2013-0127.html
Bugzilla
CVE-2012-2693 libvirt ignores address bus= device= when identicle vendor ID/product IDs usb devices attached with either virsh or virt-manager [fedora-all]
bugzilla·2012-04-26·CVSS 3.7
CVE-2012-2693 [LOW] CVE-2012-2693 libvirt ignores address bus= device= when identicle vendor ID/product IDs usb devices attached with either virsh or virt-manager [fedora-all]
CVE-2012-2693 libvirt ignores address bus= device= when identicle vendor ID/product IDs usb devices attached with either virsh or virt-manager [fedora-all]
+++ This bug was initially created as a clone of Bug #815755 +++
Description of problem:
Version-Release number of selected component (if applicable):
How reproducible: 100%
Steps to Reproduce:
1. Take 2 RSA Tokens and connect them to a hypervisor
2. Use lsusb -v to find a uniquely identifyable property of each device
3. Either
a) use virt-manager to attach the device with highest bus:device address to a guest
OR
b) write an XML description of the device specifying address bus= device= for the highest numbered RSA token
# virsh attach-device
4) use virsh dumpxml and see which device is actually attached to the guest
Actual resu
http://rhn.redhat.com/errata/RHSA-2012-0748.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0127.htmlhttp://www.openwall.com/lists/oss-security/2012/06/11/2http://www.openwall.com/lists/oss-security/2012/06/11/3https://www.redhat.com/archives/libvir-list/2012-April/msg01494.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0748.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0127.htmlhttp://www.openwall.com/lists/oss-security/2012/06/11/2http://www.openwall.com/lists/oss-security/2012/06/11/3https://www.redhat.com/archives/libvir-list/2012-April/msg01494.html
2012-06-17
Published