PT-2010-2090 · Linux+1 · Kvm+1
Eugene Teo
+1
·
Published
2010-02-09
·
Updated
2024-06-27
·
CVE-2010-0298
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
KVM version 83
Description
The issue concerns the x86 emulator in KVM, which fails to properly use the Current Privilege Level (CPL) and I/O Privilege Level (IOPL) when determining memory access for CPL3 code. This allows users of the guest OS to potentially cause a denial of service, resulting in a guest OS crash, or gain privileges on the guest OS. The exploitation can occur through access to either an IO port or an MMIO region.
Recommendations
For KVM version 83, update to a version that includes the necessary fixes to properly handle CPL and IOPL for memory access.
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kvm
Red Hat