UBUNTU-CVE-2012-4461
Dashboard / Vulnerabilities / UBUNTU-CVE-2012-4461
UBUNTU-CVE-2012-4461
Summary:
Details: The KVM subsystem in the Linux kernel before 3.6.9, when running on hosts that use qemu userspace without XSAVE, allows local users to cause a denial of service (kernel OOPS) by using the KVM_SET_SREGS ioctl to set the X86_CR4_OSXSAVE bit in the guest cr4 register, then calling the KVM_RUN ioctl.
References: https://ubuntu.com/security/CVE-2012-4461, http://www.openwall.com/lists/oss-security/2012/11/06/14, http://article.gmane.org/gmane.comp.emulators.kvm.devel/100742, https://ubuntu.com/security/notices/USN-1688-1, https://ubuntu.com/security/notices/USN-1689-1, https://ubuntu.com/security/notices/USN-1696-1, https://ubuntu.com/security/notices/USN-1699-1, https://ubuntu.com/security/notices/USN-1704-1, https://www.cve.org/CVERecord?id=CVE-2012-4461
Affected packages
Package
Name: linux
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
