Back to search
CVE-2009-3640
Published: Oct 29, 2009
Modified: Aug 7, 2024
PUBLISHED
Description
The update_cr8_intercept function in arch/x86/kvm/x86.c in the KVM subsystem in the Linux kernel before 2.6.32-rc1 does not properly handle the absence of an Advanced Programmable Interrupt Controller (APIC), which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly gain privileges via a call to the kvm_vcpu_ioctl function.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
[oss-security] 20091023 CVE request: kvm: update_cr8_intercept() NULL pointer dereference
mailing-list
x_refsource_MLIST
[oss-security] 20091024 Re: CVE request: kvm: update_cr8_intercept() NULL pointer dereference
mailing-list
x_refsource_MLIST
36805
vdb-entry
x_refsource_BID
http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.32-rc1
x_refsource_CONFIRM
kernel-updatecr8intercept-dos(53947)
vdb-entry
x_refsource_XF
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now