PT-2010-2100 · Linux+1 · Kvm+1
Eugene Teo
·
Published
2010-02-09
·
Updated
2023-02-13
·
CVE-2010-0309
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
KVM version 83
Description
The issue arises from the pit ioport read function in the Programmable Interval Timer (PIT) emulation, specifically in the i8254.c file. This function does not properly utilize the pit state data structure, allowing guest OS users to cause a denial of service. This can be achieved by attempting to read the /dev/port file, potentially leading to a host OS crash or hang.
Recommendations
For KVM version 83, consider applying a patch that corrects the pit ioport read function's usage of the pit state data structure to prevent denial of service attacks. As a temporary workaround, restrict access to the /dev/port file to minimize the risk of exploitation.
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kvm
Red Hat