CVE-2009-2287
01.07.2009, 13:00
The kvm_arch_vcpu_ioctl_set_sregs function in the KVM in Linux kernel 2.6 before 2.6.30, when running on x86 systems, does not validate the page table root in a KVM_SET_SREGS call, which allows local users to cause a denial of service (crash or hang) via a crafted cr3 value, which triggers a NULL pointer dereference in the gfn_to_rmap function.Enginsight
Vendor | Product | Version |
---|---|---|
linux | linux_kernel | 2.6.0 ≤ 𝑥 < 2.6.30 |
canonical | ubuntu_linux | 6.06 |
canonical | ubuntu_linux | 8.04 |
canonical | ubuntu_linux | 8.10 |
canonical | ubuntu_linux | 9.04 |
debian | debian_linux | 4.0 |
debian | debian_linux | 5.0 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Ubuntu Product | |||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
kvm |
| ||||||||||||||||
linux |
| ||||||||||||||||
linux-ec2 |
| ||||||||||||||||
linux-fsl-imx51 |
| ||||||||||||||||
linux-lts-backport-maverick |
| ||||||||||||||||
linux-mvl-dove |
| ||||||||||||||||
linux-source-2.6.15 |
| ||||||||||||||||
linux-ti-omap4 |
| ||||||||||||||||
qemu-kvm |
|
Common Weakness Enumeration
References