CVE-2012-1601
The KVM implementation in the Linux kernel before 3.3.6 allows host OS users to cause a denial of service (NULL pointer dereference and host OS crash) by making a KVM_CREATE_IRQCHIP ioctl call after a virtual CPU already exists.
- Affected products
- Centos, Linux Kernel, Red Hat, Suse, Libvmtools0, Libvmtools0-Debuginfo, Linux-2.6, Systemtap
- Linux Linux Kernel
- β€ 3.3.5
- Fix
- Available
- CVSS 2.0
- 4.9 MEDIUM
- EPSS
- 0.4% (34th percentile)
- Weakness
- CWE-399
- NVD status
- Modified
- Published
- 2012-05-17
CVE-2012-1601 at NVD
1 known exploit for CVE-2012-1601
Proof-of-concept code and exploit modules indexed by Sploitus