CVE-2011-4347
Last modified
CVE-2011-4347 is a vulnerability of currently unknown severity. The kvm_vm_ioctl_assign_device function in virt/kvm/assigned-dev.c in the KVM subsystem in the Linux kernel before 3.1.10 does not verify permission to access PCI configuration space and BAR resources, which allows host OS users to assign PCI devices and cause a denial of service (host OS crash) via a KVM_ASSIGN_PCI_DEVICE operation.. EPSS estimates a 0.37% chance of exploitation in the next 30 days.
Description
The kvm_vm_ioctl_assign_device function in virt/kvm/assigned-dev.c in the KVM subsystem in the Linux kernel before 3.1.10 does not verify permission to access PCI configuration space and BAR resources, which allows host OS users to assign PCI devices and cause a denial of service (host OS crash) via a KVM_ASSIGN_PCI_DEVICE operation.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | <= 3.1.9 |
| Linux | Linux Kernel | 3.1.1 |
| Linux | Linux Kernel | 3.1.2 |
| Linux | Linux Kernel | 3.1.3 |
| Linux | Linux Kernel | 3.1.4 |
| Linux | Linux Kernel | 3.1.5 |
| Linux | Linux Kernel | 3.1.6 |
| Linux | Linux Kernel | 3.1.7 |
| Linux | Linux Kernel | 3.1.8 |
References
- https://bugzilla.redhat.com/show_bug.cgi?id=756084Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=756084Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2011-4347?
How severe is CVE-2011-4347?
How do I fix CVE-2011-4347?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2011
- CVE-2011-4341Multiple SQL injection vulnerabilities in symphony/content/c…
- CVE-2011-4342PHP remote file inclusion vulnerability in wp_xml_export.php…
- CVE-2011-4343Information disclosure vulnerability in Apache MyFaces Core …
- CVE-2011-4344Cross-site scripting (XSS) vulnerability in Jenkins Core in …
- CVE-2011-4345Cross-site scripting (XSS) vulnerability in Namazu before 2.…
- CVE-2011-4346Cross-site scripting (XSS) vulnerability in the web interfac…
- CVE-2011-4348Race condition in the sctp_rcv function in net/sctp/input.c …
- CVE-2011-4349Multiple SQL injection vulnerabilities in (1) cd-mapping-db.…
- CVE-2011-4350Yaws 1.91 has a directory traversal vulnerability in the way…6.5
- CVE-2011-4351Buffer overflow in FFmpeg before 0.5.6, 0.6.x before 0.6.4, …
- CVE-2011-4352Integer overflow in the vp3_dequant function in the VP3 deco…
- CVE-2011-4353The (1) av_image_fill_pointers, (2) vp5_parse_coeff, and (3)…
Are you affected by CVE-2011-4347?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
