SB2013012303 - Buffer overflow in Linux kernel



SB2013012303 - Buffer overflow in Linux kernel

Published: January 23, 2013 Updated: August 11, 2020

Security Bulletin ID SB2013012303
Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Buffer overflow (CVE-ID: CVE-2012-2137)

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

Buffer overflow in virt/kvm/irq_comm.c in the KVM subsystem in the Linux kernel before 3.2.24 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to Message Signaled Interrupts (MSI), irq routing entries, and an incorrect check by the setup_routing_entry function before invoking the kvm_set_irq function.


Remediation

Install update from vendor's website.