PT-2010-2090 · Linux+1 · Kvm+1

Eugene Teo

+1

·

Published

2010-02-09

·

Updated

2024-06-27

·

CVE-2010-0298

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions KVM version 83
Description The issue concerns the x86 emulator in KVM, which fails to properly use the Current Privilege Level (CPL) and I/O Privilege Level (IOPL) when determining memory access for CPL3 code. This allows users of the guest OS to potentially cause a denial of service, resulting in a guest OS crash, or gain privileges on the guest OS. The exploitation can occur through access to either an IO port or an MMIO region.
Recommendations For KVM version 83, update to a version that includes the necessary fixes to properly handle CPL and IOPL for memory access.

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-6514
CVE-2010-0298
DSA-1996-1
DSA-2010-1
RHSA-2010:0088
RHSA-2010:0095
RHSA-2010_0088

Affected Products

Kvm
Red Hat