CVE-2009-4031
The do_insn_fetch function in arch/x86/kvm/emulate.c in the x86 emulator in the KVM subsystem in the Linux kernel before 2.6.32-rc8-next-20091125 tries to interpret instructions that contain too many bytes to be valid, which allows guest OS users to…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.11%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The do_insn_fetch function in arch/x86/kvm/emulate.c in the x86 emulator in the KVM subsystem in the Linux kernel before 2.6.32-rc8-next-20091125 tries to interpret instructions that contain too many bytes to be valid, which allows guest OS users to cause a denial of service (increased scheduling latency) on the host OS via unspecified manipulations related to SMP support.
- CVSS 2.0
- 7.8 HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
- EPSS
- 3.11% probability · 87th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- linux/linux kernel
- Source
- secalert@redhat.com
References
- http://git.kernel.org/?p=linux/kernel/git/avi/kvm.git%3Ba=commit%3Bh=e42d9b8141d1f54ff72ad3850bb110c95a5f3b88
- http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00006.htmlThird Party Advisory
- http://secunia.com/advisories/37720Third Party Advisory
- http://www.kernel.org/pub/linux/kernel/v2.6/next/patch-v2.6.32-rc8-next-20091125.gzPatch, Vendor Advisory
- http://www.openwall.com/lists/oss-security/2009/11/25/1Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2009/11/25/3Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/37130Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=541160Issue Tracking, Third Party Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11089Third Party Advisory
- https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00777.htmlThird Party Advisory
- http://git.kernel.org/?p=linux/kernel/git/avi/kvm.git%3Ba=commit%3Bh=e42d9b8141d1f54ff72ad3850bb110c95a5f3b88
- http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00006.htmlThird Party Advisory
- http://secunia.com/advisories/37720Third Party Advisory
- http://www.kernel.org/pub/linux/kernel/v2.6/next/patch-v2.6.32-rc8-next-20091125.gzPatch, Vendor Advisory
- http://www.openwall.com/lists/oss-security/2009/11/25/1Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2009/11/25/3Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/37130Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=541160Issue Tracking, Third Party Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11089Third Party Advisory
- https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00777.htmlThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.