CVE-2010-0298
12.02.2010, 19:30
The x86 emulator in KVM 83 does not use the Current Privilege Level (CPL) and I/O Privilege Level (IOPL) in determining the memory access available to CPL3 code, which allows guest OS users to cause a denial of service (guest OS crash) or gain privileges on the guest OS by leveraging access to a (1) IO port or (2) MMIO region, a related issue to CVE-2010-0306.Enginsight
Vendor | Product | Version |
---|---|---|
linux | linux_kernel | 2.6.28 ≤ 𝑥 ≤ 2.6.33 |
debian | debian_linux | 5.0 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Ubuntu Product | |||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
kvm |
| ||||||||||||||||
linux |
| ||||||||||||||||
linux-ec2 |
| ||||||||||||||||
linux-fsl-imx51 |
| ||||||||||||||||
linux-lts-backport-maverick |
| ||||||||||||||||
linux-mvl-dove |
| ||||||||||||||||
linux-source-2.6.15 |
| ||||||||||||||||
linux-ti-omap4 |
|
Common Weakness Enumeration
References