PT-2010-2100 · Linux+1 · Kvm+1
CVSS v2.0
6.8
Média
| Vetor | AV:N/AC:L/Au:S/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
KVM version 83
Description
The issue arises from the pit ioport read function in the Programmable Interval Timer (PIT) emulation, specifically in the i8254.c file. This function does not properly utilize the pit state data structure, allowing guest OS users to cause a denial of service. This can be achieved by attempting to read the /dev/port file, potentially leading to a host OS crash or hang.
Recommendations
For KVM version 83, consider applying a patch that corrects the pit ioport read function's usage of the pit state data structure to prevent denial of service attacks. As a temporary workaround, restrict access to the /dev/port file to minimize the risk of exploitation.
Correção
DoS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Kvm
Red Hat