7.4
CVSSv2

CVE-2011-2212

Published: 21/06/2012 Updated: 13/02/2023
CVSS v2 Base Score: 7.4 | Impact Score: 10 | Exploitability Score: 4.4
VMScore: 659
Vector: AV:A/AC:M/Au:S/C:C/I:C/A:C

Vulnerability Summary

Buffer overflow in the virtio subsystem in qemu-kvm 0.14.0 and previous versions allows privileged guest users to cause a denial of service (guest crash) or gain privileges via a crafted indirect descriptor related to "virtqueue in and out requests."

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

qemu qemu 0.12.2

qemu qemu 0.12.0

qemu qemu 0.1.6

qemu qemu 0.13.0

qemu qemu 0.5.3

qemu qemu 0.4.2

qemu qemu 0.10.3

qemu qemu 0.11.0-rc1

qemu qemu 0.1.5

qemu qemu 0.5.1

qemu qemu 0.8.2

qemu qemu 0.11.0

qemu qemu 0.5.5

qemu qemu 0.10.1

qemu qemu 0.9.0

qemu qemu 0.7.2

qemu qemu 0.12.5

qemu qemu 0.1.3

qemu qemu 0.14.0

qemu qemu 0.11.1

qemu qemu 0.7.1

qemu qemu 0.9.1-5

qemu qemu

qemu qemu 0.5.0

qemu qemu 0.8.1

qemu qemu 0.11.0-rc2

qemu qemu 0.10.0

qemu qemu 0.4.1

qemu qemu 0.5.2

qemu qemu 0.12.3

qemu qemu 0.1.1

qemu qemu 0.7.0

qemu qemu 0.1.4

qemu qemu 0.9.1

qemu qemu 0.6.0

qemu qemu 0.6.1

qemu qemu 0.10.6

qemu qemu 0.11.0-rc0

qemu qemu 0.4.3

qemu qemu 0.1.2

qemu qemu 0.5.4

qemu qemu 0.12.4

qemu qemu 0.10.5

qemu qemu 0.10.4

qemu qemu 0.10.2

qemu qemu 0.12.1

qemu qemu 0.8.0

qemu qemu 0.1.0

qemu qemu 0.2.0

qemu qemu 0.3.0

qemu qemu 0.4.0

Vendor Advisories

A privileged attacker within a QEMU guest could cause QEMU to crash ...
Two vulnerabilities have been discovered in KVM, a solution for full virtualization on x86 hardware: CVE-2011-2212 Nelson Elhage discovered a buffer overflow in the virtio subsystem, which could lead to denial of service or privilege escalation CVE-2011-2527 Andrew Griffiths discovered that group privileges were insufficiently dropped ...