CVE-2012-3221

low
Published 2012-10-17 · Modified 2026-04-29
CVSS v3
CVSS v2
2.1
VIR risk
2.1

Description

Unspecified vulnerability in the Oracle VM Virtual Box component in Oracle Virtualization 3.2, 4.0, and 4.1 allows local users to affect availability via unknown vectors related to VirtualBox Core. NOTE: The previous information was obtained from the October 2012 CPU. Oracle has not commented on claims from another vendor that this issue is related to "incorrect interrupt handling."

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2012-3221

vendor Authored 2026-05-27

Vendor advisory: secalert_us@oracle.com — http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html

OS impact

OSVersionStatusFixed in
debian debiansidfixed4.1.18-dfsg-1.1

Application impact

VendorProductVersionsFixed
oraclevirtualization3.2
oraclevirtualization4.0
oraclevirtualization4.1

References

Verify integrity in audit chain (admin only). AS-IS.