CVE-2012-2693
Summary
| CVE | CVE-2012-2693 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2012-06-17 03:41:42 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | libvirt, possibly before 0.9.12, does not properly assign USB devices to virtual machines when multiple devices have the same vendor and product ID, which might cause the wrong device to be associated with a guest and might allow local users to access unintended USB devices. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
HighAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:L/AC:H/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Redhat | Libvirt | 0.0.1 | All | All | All |
| Application | Redhat | Libvirt | 0.0.2 | All | All | All |
| Application | Redhat | Libvirt | 0.0.3 | All | All | All |
| Application | Redhat | Libvirt | 0.0.4 | All | All | All |
| Application | Redhat | Libvirt | 0.0.5 | All | All | All |
| Application | Redhat | Libvirt | 0.0.6 | All | All | All |
| Application | Redhat | Libvirt | 0.1.0 | All | All | All |
| Application | Redhat | Libvirt | 0.1.1 | All | All | All |
| Application | Redhat | Libvirt | 0.1.3 | All | All | All |
| Application | Redhat | Libvirt | 0.1.4 | All | All | All |
| Application | Redhat | Libvirt | 0.1.5 | All | All | All |
| Application | Redhat | Libvirt | 0.1.6 | All | All | All |
| Application | Redhat | Libvirt | 0.1.7 | All | All | All |
| Application | Redhat | Libvirt | 0.1.8 | All | All | All |
| Application | Redhat | Libvirt | 0.1.9 | All | All | All |
| Application | Redhat | Libvirt | 0.2.0 | All | All | All |
| Application | Redhat | Libvirt | 0.2.1 | All | All | All |
| Application | Redhat | Libvirt | 0.2.2 | All | All | All |
| Application | Redhat | Libvirt | 0.2.3 | All | All | All |
| Application | Redhat | Libvirt | 0.3.0 | All | All | All |
| Application | Redhat | Libvirt | 0.3.1 | All | All | All |
| Application | Redhat | Libvirt | 0.3.2 | All | All | All |
| Application | Redhat | Libvirt | 0.3.3 | All | All | All |
| Application | Redhat | Libvirt | 0.4.0 | All | All | All |
| Application | Redhat | Libvirt | 0.4.1 | All | All | All |
| Application | Redhat | Libvirt | 0.4.2 | All | All | All |
| Application | Redhat | Libvirt | 0.4.3 | All | All | All |
| Application | Redhat | Libvirt | 0.4.4 | All | All | All |
| Application | Redhat | Libvirt | 0.4.5 | All | All | All |
| Application | Redhat | Libvirt | 0.4.6 | All | All | All |
| Application | Redhat | Libvirt | 0.5.0 | All | All | All |
| Application | Redhat | Libvirt | 0.5.1 | All | All | All |
| Application | Redhat | Libvirt | 0.6.0 | All | All | All |
| Application | Redhat | Libvirt | 0.6.1 | All | All | All |
| Application | Redhat | Libvirt | 0.6.2 | All | All | All |
| Application | Redhat | Libvirt | 0.6.3 | All | All | All |
| Application | Redhat | Libvirt | 0.6.4 | All | All | All |
| Application | Redhat | Libvirt | 0.6.5 | All | All | All |
| Application | Redhat | Libvirt | 0.7.0 | All | All | All |
| Application | Redhat | Libvirt | 0.7.1 | All | All | All |
| Application | Redhat | Libvirt | 0.7.2 | All | All | All |
| Application | Redhat | Libvirt | 0.7.3 | All | All | All |
| Application | Redhat | Libvirt | 0.7.4 | All | All | All |
| Application | Redhat | Libvirt | 0.7.5 | All | All | All |
| Application | Redhat | Libvirt | 0.7.6 | All | All | All |
| Application | Redhat | Libvirt | 0.7.7 | All | All | All |
| Application | Redhat | Libvirt | 0.8.0 | All | All | All |
| Application | Redhat | Libvirt | 0.8.1 | All | All | All |
| Application | Redhat | Libvirt | 0.8.2 | All | All | All |
| Application | Redhat | Libvirt | 0.8.3 | All | All | All |
| Application | Redhat | Libvirt | 0.8.4 | All | All | All |
| Application | Redhat | Libvirt | 0.8.5 | All | All | All |
| Application | Redhat | Libvirt | 0.8.6 | All | All | All |
| Application | Redhat | Libvirt | 0.8.7 | All | All | All |
| Application | Redhat | Libvirt | 0.8.8 | All | All | All |
| Application | Redhat | Libvirt | 0.9.0 | All | All | All |
| Application | Redhat | Libvirt | 0.9.1 | All | All | All |
| Application | Redhat | Libvirt | 0.9.10 | All | All | All |
| Application | Redhat | Libvirt | 0.9.2 | All | All | All |
| Application | Redhat | Libvirt | 0.9.3 | All | All | All |
| Application | Redhat | Libvirt | 0.9.4 | All | All | All |
| Application | Redhat | Libvirt | 0.9.5 | All | All | All |
| Application | Redhat | Libvirt | 0.9.6 | All | All | All |
| Application | Redhat | Libvirt | 0.9.7 | All | All | All |
| Application | Redhat | Libvirt | 0.9.8 | All | All | All |
| Application | Redhat | Libvirt | 0.9.9 | All | All | All |
| Application | Redhat | Libvirt | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| oss-security - CVE request -- libvirt: address bus= device= when identicle vendor ID/product IDs usb devices attached are ignored | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| oss-security - Re: CVE request -- libvirt: address bus= device= when identicle vendor ID/product IDs usb devices attached are ignored | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| [libvirt] [PATCH 0/3] usb devices with same vendor, productID hotplug su | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Patch |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.