LWN.net Logo

qemu-kvm: privilege escalation

Package(s):qemu-kvm CVE #(s):CVE-2011-4111
Created:December 7, 2011 Updated:December 22, 2011
Description: From the Red Hat advisory: A flaw was found in the way qemu-kvm handled VSC_ATR messages when a guest was configured for a CCID (Chip/Smart Card Interface Devices) USB smart card reader in passthrough mode. An attacker able to connect to the port on the host being used for such a device could use this flaw to crash the qemu-kvm process on the host or, possibly, escalate their privileges on the host.
Alerts:
CentOS CESA-2011:1777 2011-12-22
CentOS CESA-2011:1801 2011-12-22
Oracle ELSA-2011-1777 2011-12-17
Red Hat RHSA-2011:1801-01 2011-12-08
Red Hat RHSA-2011:1777-01 2011-12-06
Scientific Linux SL-qemu-20111206 2011-12-06

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds