4.9 Medium
CVSS2
Attack Vector
LOCAL
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
COMPLETE
AV:L/AC:L/Au:N/C:N/I:N/A:C
0.0004 Low
EPSS
Percentile
5.1%
The create_pit_timer function in arch/x86/kvm/i8254.c in KVM 83, and
possibly other versions, does not properly handle when Programmable
Interval Timer (PIT) interrupt requests (IRQs) when a virtual interrupt
controller (irqchip) is not available, which allows local users to cause a
denial of service (NULL pointer dereference) by starting a timer.
BUG: unable to handle kernel NULL pointer dereference at
0000000000000128
IP: [<ffffffffa10f6280>] kvm_set_irq+0x30/0x170 [kvm]
…
Call Trace:
[<ffffffffa11228c1>] pit_do_work+0x51/0xd0 [kvm]
[<ffffffff81071431>] process_one_work+0x111/0x4d0
[<ffffffff81071bb2>] worker_thread+0x152/0x340
[<ffffffff81075c8e>] kthread+0x7e/0x90
[<ffffffff815a4474>] kernel_thread_helper+0x4/0x10
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
ubuntu | 10.04 | noarch | linux | < 2.6.32-39.86 | UNKNOWN |
ubuntu | 10.10 | noarch | linux | < 2.6.35-32.65 | UNKNOWN |
ubuntu | 11.04 | noarch | linux | < 2.6.38-13.55 | UNKNOWN |
ubuntu | 11.10 | noarch | linux | < 3.0.0-16.27 | UNKNOWN |
ubuntu | 10.04 | noarch | linux-ec2 | < 2.6.32-343.45 | UNKNOWN |
ubuntu | 10.04 | noarch | linux-lts-backport-maverick | < 2.6.35-32.65~lucid1 | UNKNOWN |
ubuntu | 10.04 | noarch | linux-lts-backport-natty | < 2.6.38-13.55~lucid1 | UNKNOWN |
ubuntu | 10.04 | noarch | linux-lts-backport-oneiric | < 3.0.0-16.28~lucid1 | UNKNOWN |
permalink.gmane.org/gmane.comp.emulators.kvm.devel/83564
launchpad.net/bugs/cve/CVE-2011-4622
nvd.nist.gov/vuln/detail/CVE-2011-4622
security-tracker.debian.org/tracker/CVE-2011-4622
ubuntu.com/security/notices/USN-1361-1
ubuntu.com/security/notices/USN-1362-1
ubuntu.com/security/notices/USN-1363-1
ubuntu.com/security/notices/USN-1384-1
ubuntu.com/security/notices/USN-1386-1
ubuntu.com/security/notices/USN-1387-1
ubuntu.com/security/notices/USN-1388-1
ubuntu.com/security/notices/USN-1389-1
www.cve.org/CVERecord?id=CVE-2011-4622