CVE Database
/

CVE-2010-0306

Back to search

CVE-2010-0306

Published: Feb 12, 2010

Modified: Aug 7, 2024

PUBLISHED

Description

The x86 emulator in KVM 83, when a guest is configured for Symmetric Multiprocessing (SMP), does not use the Current Privilege Level (CPL) and I/O Privilege Level (IOPL) to restrict instruction execution, which allows guest OS users to cause a denial of service (guest OS crash) or gain privileges on the guest OS by leveraging access to a (1) IO port or (2) MMIO region, and replacing an instruction in between emulator entry and instruction fetch, a related issue to CVE-2010-0298.

VendorProductVersions

n/a

n/a

affected
n/a

References

38158
vdb-entry
x_refsource_BID
RHSA-2010:0088
vendor-advisory
x_refsource_REDHAT
oval:org.mitre.oval:def:10953
vdb-entry
signature
x_refsource_OVAL
DSA-1996
vendor-advisory
x_refsource_DEBIAN
RHSA-2010:0095
vendor-advisory
x_refsource_REDHAT
38499
third-party-advisory
x_refsource_SECUNIA
38492
third-party-advisory
x_refsource_SECUNIA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now