CVE-2011-4347
Linux Kernel < 3.1.10 - Denial of Service via KVM_ASSIGN_PCI_DEVICE Operation
Title source: llmDescription
The kvm_vm_ioctl_assign_device function in virt/kvm/assigned-dev.c in the KVM subsystem in the Linux kernel before 3.1.10 does not verify permission to access PCI configuration space and BAR resources, which allows host OS users to assign PCI devices and cause a denial of service (host OS crash) via a KVM_ASSIGN_PCI_DEVICE operation.
References (4)
Core 4
Core References
Patch x_refsource_confirm
https://github.com/torvalds/linux/commit/c4e7f9022e506c6635a5037713c37118e23193e4
Mailing List mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2011/11/24/7
Vendor Advisory x_refsource_confirm
http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.1.10
Vendor Advisory x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=756084
Scores
EPSS
0.0037
EPSS Percentile
29.6%
Details
CWE
CWE-264
Status
published
Products (9)
linux/linux_kernel
3.1.1
linux/linux_kernel
3.1.2
linux/linux_kernel
3.1.3
linux/linux_kernel
3.1.4
linux/linux_kernel
3.1.5
linux/linux_kernel
3.1.6
linux/linux_kernel
3.1.7
linux/linux_kernel
3.1.8
linux/linux_kernel
< 3.1.9
Published
Jun 08, 2013
Tracked Since
Feb 18, 2026