CVE-2009-4004
20.11.2009, 02:30
Buffer overflow in the kvm_vcpu_ioctl_x86_setup_mce function in arch/x86/kvm/x86.c in the KVM subsystem in the Linux kernel before 2.6.32-rc7 allows local users to cause a denial of service (memory corruption) or possibly gain privileges via a KVM_X86_SETUP_MCE IOCTL request that specifies a large number of Machine Check Exception (MCE) banks.Enginsight
Vendor | Product | Version |
---|---|---|
linux | linux_kernel | 𝑥 ≤ 2.6.31.14 |
linux | linux_kernel | 2.6.32 |
linux | linux_kernel | 2.6.32:rc1 |
linux | linux_kernel | 2.6.32:rc2 |
linux | linux_kernel | 2.6.32:rc3 |
linux | linux_kernel | 2.6.32:rc4 |
linux | linux_kernel | 2.6.32:rc5 |
linux | linux_kernel | 2.6.32:rc6 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration
References