CVE-2011-2512
Publication date 5 July 2011
Last updated 24 July 2024
Ubuntu priority
The virtio_queue_notify in qemu-kvm 0.14.0 and earlier does not properly validate the virtqueue number, which allows guest users to cause a denial of service (guest crash) and possibly execute arbitrary code via a negative number in the Queue Notify field of the Virtio Header, which bypasses a signed comparison.
Status
Package | Ubuntu Release | Status |
---|---|---|
qemu-kvm | ||
Patch details
Package | Patch details |
---|---|
qemu-kvm |
References
Related Ubuntu Security Notices (USN)
- USN-1165-1
- QEMU vulnerabilities
- 6 July 2011