Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2011-4622

18
FAUCET Score

CVE-2011-4622 describes a denial-of-service vulnerability in KVM 83 and potentially other versions, specifically within the create_pit_timer function in arch/x86/kvm/i8254.c. This flaw occurs when the Programmable Interval Timer (PIT) interrupt requests are mishandled due to the absence of a virtual interrupt controller, allowing local users to trigger a NULL pointer dereference by starting a timer. With a CVSS score of 4.9 (AV:L/AC:L/Au:N/C:N/I:N/A:C), this vulnerability has a low attack complexity and requires local access, leading to a complete loss of availability. There is no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage, indicating a low current threat profile.

Impacted Technologies

VendorProductVersion(s)CPE
83CPE matchmatch criteria
cpe:2.3:a:redhat:kvm:83:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

4.9MEDIUM

AV:L/AC:L/Au:N/C:N/I:N/A:C

Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
COMPLETE
Access Vector
LOCAL
Access Complexity
LOW
Authentication
NONE
Exploitability Score
3.9
Impact Score
6.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
0.36%
Probability of exploitation in next 30 days
EPSS Percentile
28.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0036 is in the 47th percentile among its peer group of 3,049 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: kvm-0:83-239.el5_7.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: kernel-0:2.6.32-220.7.1.el6
View patch
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: kvm

Vendor Advisories (1)

redhatCVE-2011-4622Moderate

kernel: kvm: pit timer with no irqchip crashes the system

Dec 14, 2011

References

lists.opensuse.org / opensuse-security-announce/2012-05/msg00013.html
lists.opensuse.org / opensuse-security-announce/2013-06/msg00005.html
permalink.gmane.org / gmane.comp.emulators.kvm.devel/83564
Patch
bugzilla.redhat.com / show_bug.cgi
openwall.com / lists/oss-security/2011/12/21/7
redhat.com / support/errata/RHSA-2012-0051.html
securityfocus.com / bid/51172
securitytracker.com / id