PT-2010-2100 · Linux+1 · Kvm+1

Eugene Teo

·

Published

2010-02-09

·

Updated

2023-02-13

·

CVE-2010-0309

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions KVM version 83
Description The issue arises from the pit ioport read function in the Programmable Interval Timer (PIT) emulation, specifically in the i8254.c file. This function does not properly utilize the pit state data structure, allowing guest OS users to cause a denial of service. This can be achieved by attempting to read the /dev/port file, potentially leading to a host OS crash or hang.
Recommendations For KVM version 83, consider applying a patch that corrects the pit ioport read function's usage of the pit state data structure to prevent denial of service attacks. As a temporary workaround, restrict access to the /dev/port file to minimize the risk of exploitation.

Fix

DoS

Weakness Enumeration

Related Identifiers

AZL-34841
AZL-6509
CVE-2010-0309
DSA-1996-1
DSA-2010-1
RHSA-2010:0088
RHSA-2010:0095
RHSA-2010_0088

Affected Products

Kvm
Red Hat