Unrated severityNVD Advisory· Published Jun 21, 2012· Updated Apr 29, 2026
CVE-2011-2512
CVE-2011-2512
Description
The virtio_queue_notify in qemu-kvm 0.14.0 and earlier does not properly validate the virtqueue number, which allows guest users to cause a denial of service (guest crash) and possibly execute arbitrary code via a negative number in the Queue Notify field of the Virtio Header, which bypasses a signed comparison.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
14- www.openwall.com/lists/oss-security/2011/06/28/13nvdPatch
- www.openwall.com/lists/oss-security/2011/06/29/15nvdPatch
- secunia.com/advisories/44458nvdVendor Advisory
- secunia.com/advisories/44648nvdVendor Advisory
- secunia.com/advisories/45158nvdVendor Advisory
- secunia.com/advisories/45170nvdVendor Advisory
- secunia.com/advisories/45301nvdVendor Advisory
- git.kernel.orgnvd
- lists.opensuse.org/opensuse-security-announce/2011-07/msg00007.htmlnvd
- rhn.redhat.com/errata/RHSA-2011-0919.htmlnvd
- ubuntu.com/usn/usn-1165-1nvd
- www.osvdb.org/74751nvd
- hermes.opensuse.org/messages/9605323nvd
- www.debian.org/security/2011/dsa-2270nvd
News mentions
0No linked articles in our index yet.