CVE-2012-2137: Canonical Ubuntu Linux

Medium severity, CVSS 6.9. EPSS: 0.5% chance of exploitation in the next 30 days.

Buffer overflow in virt/kvm/irq_comm.c in the KVM subsystem in the Linux kernel before 3.2.24 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to Message Signaled Interrupts (MSI), irq routing entries, and an incorrect check by the setup_routing_entry function before invoking the kvm_set_irq function.

Affected products

  • Canonical Ubuntu Linux: version 10.04 only; version 11.10 only; version 12.04 only
  • Linux Linux Kernel: from 2.6.33, before 3.0.72 (fixed in 3.0.72); from 3.1, before 3.2.24 (fixed in 3.2.24); from 3.3, before 3.4.81 (fixed in 3.4.81)

Published 2013-01-22. Last modified 2026-06-16.