CVE-2011-2512
21.06.2012, 15:55
The virtio_queue_notify in qemu-kvm 0.14.0 and earlier does not properly validate the virtqueue number, which allows guest users to cause a denial of service (guest crash) and possibly execute arbitrary code via a negative number in the Queue Notify field of the Virtio Header, which bypasses a signed comparison.Enginsight
Vendor | Product | Version |
---|---|---|
kvm_group | qemu-kvm | 𝑥 ≤ 0.14.0 |
kvm_group | qemu-kvm | 0.12 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration
References