CVE-2011-2212

Publication date 20 June 2011

Last updated 24 July 2024


Ubuntu priority

Buffer overflow in the virtio subsystem in qemu-kvm 0.14.0 and earlier allows privileged guest users to cause a denial of service (guest crash) or gain privileges via a crafted indirect descriptor related to "virtqueue in and out requests."

Read the notes from the security team

Status

Package Ubuntu Release Status
qemu-kvm 11.04 natty
Fixed 0.14.0+noroms-0ubuntu4.3
10.10 maverick
Fixed 0.12.5+noroms-0ubuntu7.8
10.04 LTS lucid
Fixed 0.12.3+noroms-0ubuntu9.12
8.04 LTS hardy Not in release

Notes


jdstrand

be careful, 0.14.1 and Debian do not have the patch

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
qemu-kvm

References

Related Ubuntu Security Notices (USN)

Other references