Release date: 2012-04-19
Updated on: 2012-04-20
Affected Systems:
Linux kernel 2.6.x
QEMU kvm
Description:
--------------------------------------------------------------------------------
Bugtraq id: 53162
Cve id: CVE-2012-2121
KVM is a Linux kernel module that allows user space programs to use the hardware virtualization functions of multiple processors.
The memory leakage vulnerability exists in KVM when unplugging the device from IOMMU ing. Some devices can be plugged into to cause memory depletion and system unavailability.
<* Source: Linux Kernel
Link: http://secunia.com/advisories/48852/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
QEMU
----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://fabrice.bellard.free.fr/qemu/