ID:4417 - Exploit for Input validation error in Linux kernel - CVE-2012-0045

 
Main Vulnerability Database Exploits ID:4417 - Exploit for Input validation error in Linux kernel - CVE-2012-0045

ID:4417 - Exploit for Input validation error in Linux kernel - CVE-2012-0045

Published: August 11, 2020


Vulnerability identifier: #VU43920
Vulnerability risk: Medium
CVE-ID: CVE-2012-0045
CWE-ID: CWE-20
Exploitation vector: Remote access
Vulnerable software:
Linux kernel

Link to public exploit:


Vulnerability description

The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.

The em_syscall function in arch/x86/kvm/emulate.c in the KVM implementation in the Linux kernel before 3.2.14 does not properly handle the 0f05 (aka syscall) opcode, which allows guest OS users to cause a denial of service (guest OS crash) via a crafted application, as demonstrated by an NASM file.


Remediation

Install update from vendor's website.