CVE-2012-1601

Linux Kernel < 3.3.5 - Denial of Service via KVM_CREATE_IRQCHIP ioctl

Title source: llm
STIX 2.1

Description

The KVM implementation in the Linux kernel before 3.3.6 allows host OS users to cause a denial of service (NULL pointer dereference and host OS crash) by making a KVM_CREATE_IRQCHIP ioctl call after a virtual CPU already exists.

References (11)

Core 11
Core References
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2012/dsa-2469
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2012/03/30/1
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2012-0571.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1026897
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/49928
Issue Tracking x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=808199
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2012-0676.html

Scores

EPSS 0.0041
EPSS Percentile 33.9%

Details

CWE
CWE-399
Status published
Products (1)
linux/linux_kernel < 3.3.5
Published May 17, 2012
Tracked Since Feb 18, 2026