CVE-2012-2137

medium
Published 2013-01-22 · Modified 2026-04-29
CVSS v3
CVSS v2
6.9
VIR risk
6.9

Description

Buffer overflow in virt/kvm/irq_comm.c in the KVM subsystem in the Linux kernel before 3.2.24 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to Message Signaled Interrupts (MSI), irq routing entries, and an incorrect check by the setup_routing_entry function before invoking the kvm_set_irq function.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2012-2137

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.2.24

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commitdiff%3Bh=f2ebd422f71cda9c791f76f85d2ca102ae34a1ed

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed3.2.20-1
debian debianbullseyefixed3.2.20-1
debian debianforkyfixed3.2.20-1
debian debiansidfixed3.2.20-1
debian debiantrixiefixed3.2.20-1
ubuntu ubuntu10.04affected
ubuntu ubuntu11.10affected
ubuntu ubuntu12.04affected
linux linux-kernelaffected3.0.72

References

CWEs

CWE-119

Verify integrity in audit chain (admin only). AS-IS.