PT-2010-2100 · Linux+1 · Kvm+1

·

CVE-2010-0309

·

Publicado

2010-02-09

·

Atualizado

2023-02-13

CVSS v2.0

6.8

Média

VetorAV:N/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions KVM version 83
Description The issue arises from the pit ioport read function in the Programmable Interval Timer (PIT) emulation, specifically in the i8254.c file. This function does not properly utilize the pit state data structure, allowing guest OS users to cause a denial of service. This can be achieved by attempting to read the /dev/port file, potentially leading to a host OS crash or hang.
Recommendations For KVM version 83, consider applying a patch that corrects the pit ioport read function's usage of the pit state data structure to prevent denial of service attacks. As a temporary workaround, restrict access to the /dev/port file to minimize the risk of exploitation.

Correção

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

AZL-34841
AZL-6509
CVE-2010-0309
DSA-1996-1
DSA-2010-1
RHSA-2010:0088
RHSA-2010:0095
RHSA-2010_0088

Produtos afetados

Kvm
Red Hat