Back to search
CVE-2009-1242
Published: Apr 6, 2009
Modified: Aug 7, 2024
PUBLISHED
Description
The vmx_set_msr function in arch/x86/kvm/vmx.c in the VMX implementation in the KVM subsystem in the Linux kernel before 2.6.29.1 on the i386 platform allows guest OS users to cause a denial of service (OOPS) by setting the EFER_LME (aka "Long mode enable") bit in the Extended Feature Enable Register (EFER) model-specific register, which is specific to the x86_64 platform.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
http://www.kernel.org/pub/linux/kernel/v2.6/snapshots/patch-2.6.29-git1.log
x_refsource_CONFIRM
linux-kernel-eferlme-dos(49594)
vdb-entry
x_refsource_XF
35226
third-party-advisory
x_refsource_SECUNIA
http://patchwork.kernel.org/patch/15549/
x_refsource_CONFIRM
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.29.1
x_refsource_CONFIRM
34478
third-party-advisory
x_refsource_SECUNIA
34331
vdb-entry
x_refsource_BID
FEDORA-2009-5356
vendor-advisory
x_refsource_FEDORA
SUSE-SA:2009:032
vendor-advisory
x_refsource_SUSE
35656
third-party-advisory
x_refsource_SECUNIA
20090516 rPSA-2009-0084-1 kernel
mailing-list
x_refsource_BUGTRAQ
35120
third-party-advisory
x_refsource_SECUNIA
SUSE-SA:2009:031
vendor-advisory
x_refsource_SUSE
USN-793-1
vendor-advisory
x_refsource_UBUNTU
34981
third-party-advisory
x_refsource_SECUNIA
DSA-1800
vendor-advisory
x_refsource_DEBIAN
35387
third-party-advisory
x_refsource_SECUNIA
DSA-1787
vendor-advisory
x_refsource_DEBIAN
http://wiki.rpath.com/Advisories:rPSA-2009-0084
x_refsource_CONFIRM
[oss-security] 20090401 CVE request: kernel: KVM: VMX: Dont allow uninhibited access to EFER on i386
mailing-list
x_refsource_MLIST
35121
third-party-advisory
x_refsource_SECUNIA
ADV-2009-0924
vdb-entry
x_refsource_VUPEN
https://bugzilla.redhat.com/show_bug.cgi?id=502109
x_refsource_CONFIRM
35394
third-party-advisory
x_refsource_SECUNIA
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now