PT-2010-2090 · Linux+1 · Kvm+1
Eugene Teo
+1
·
Publicado
2010-02-09
·
Atualizado
2024-06-27
·
CVE-2010-0298
CVSS v2.0
6.5
Média
| Vetor | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
KVM version 83
Description
The issue concerns the x86 emulator in KVM, which fails to properly use the Current Privilege Level (CPL) and I/O Privilege Level (IOPL) when determining memory access for CPL3 code. This allows users of the guest OS to potentially cause a denial of service, resulting in a guest OS crash, or gain privileges on the guest OS. The exploitation can occur through access to either an IO port or an MMIO region.
Recommendations
For KVM version 83, update to a version that includes the necessary fixes to properly handle CPL and IOPL for memory access.
Correção
DoS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Kvm
Red Hat