VulnerabilityModified
CVE-2010-3698
The KVM implementation in the Linux kernel before 2.6.36 does not properly reload the FS and GS segment registers, which allows host OS users to cause a denial of service (host OS crash) via a KVM_RUN ioctl call in conjunction with a modified Local…
MEDIUM 4.9EPSS 0.42%
Does this matter?
Lower severity and a low EPSS score (0.42%). Track it; it rarely justifies an emergency change on its own.
Description
The KVM implementation in the Linux kernel before 2.6.36 does not properly reload the FS and GS segment registers, which allows host OS users to cause a denial of service (host OS crash) via a KVM_RUN ioctl call in conjunction with a modified Local Descriptor Table (LDT).
- CVSS 2.0
- 4.9 MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
- EPSS
- 0.42% probability · 36th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-400
- Affected
- linux/linux kernel · fedoraproject/fedora
- Source
- secalert@redhat.com
References
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=9581d442b9058d3699b4be568b6e5eae38a41493
- http://lists.fedoraproject.org/pipermail/package-announce/2010-December/052513.htmlThird Party Advisory
- http://secunia.com/advisories/42745Third Party Advisory
- http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.36Broken Link
- http://www.mandriva.com/security/advisories?name=MDVSA-2011:029Third Party Advisory
- http://www.redhat.com/support/errata/RHSA-2010-0842.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2010-0898.htmlThird Party Advisory
- http://www.securityfocus.com/bid/44500Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2010/3123Third Party Advisory
- http://www.vupen.com/english/advisories/2010/3321Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=639879Issue Tracking, Third Party Advisory
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=9581d442b9058d3699b4be568b6e5eae38a41493
- http://lists.fedoraproject.org/pipermail/package-announce/2010-December/052513.htmlThird Party Advisory
- http://secunia.com/advisories/42745Third Party Advisory
- http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.36Broken Link
- http://www.mandriva.com/security/advisories?name=MDVSA-2011:029Third Party Advisory
- http://www.redhat.com/support/errata/RHSA-2010-0842.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2010-0898.htmlThird Party Advisory
- http://www.securityfocus.com/bid/44500Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2010/3123Third Party Advisory
- http://www.vupen.com/english/advisories/2010/3321Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=639879Issue Tracking, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.