Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2009-2287

Опубликовано: 01 июл. 2009
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4.9

Описание

The kvm_arch_vcpu_ioctl_set_sregs function in the KVM in Linux kernel 2.6 before 2.6.30, when running on x86 systems, does not validate the page table root in a KVM_SET_SREGS call, which allows local users to cause a denial of service (crash or hang) via a crafted cr3 value, which triggers a NULL pointer dereference in the gfn_to_rmap function.

РелизСтатусПримечание
dapper

DNE

devel

DNE

hardy

ignored

end of life
intrepid

ignored

end of life, was needed
jaunty

ignored

end of life
karmic

DNE

lucid

DNE

maverick

DNE

natty

DNE

upstream

released

85+dfsg-4

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

not-affected

2.6.31.1.11
hardy

released

2.6.24-24.57
intrepid

released

2.6.27-14.37
jaunty

released

2.6.28-14.47
karmic

not-affected

2.6.31.1.11
lucid

not-affected

2.6.31.1.11
maverick

not-affected

2.6.31.1.11
natty

not-affected

2.6.31.1.11
upstream

released

2.6.31~rc1

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

DNE

hardy

DNE

intrepid

DNE

jaunty

DNE

karmic

not-affected

2.6.31.1.11
lucid

not-affected

2.6.31.1.11
maverick

ignored

end of life
natty

DNE

upstream

released

2.6.31~rc1

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

DNE

hardy

DNE

karmic

not-affected

lucid

not-affected

maverick

DNE

natty

DNE

upstream

released

2.6.31~rc1

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

DNE

hardy

DNE

intrepid

DNE

jaunty

DNE

karmic

DNE

lucid

not-affected

maverick

DNE

natty

DNE

upstream

released

2.6.31~rc1

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

DNE

hardy

DNE

karmic

ignored

end of life
lucid

not-affected

maverick

not-affected

natty

DNE

upstream

released

2.6.31~rc1

Показывать по

РелизСтатусПримечание
dapper

released

2.6.15-54.78
devel

DNE

hardy

DNE

intrepid

DNE

jaunty

DNE

karmic

DNE

lucid

DNE

maverick

DNE

natty

DNE

upstream

released

2.6.31~rc1

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

not-affected

hardy

DNE

karmic

DNE

lucid

DNE

maverick

not-affected

natty

not-affected

upstream

released

2.6.31~rc1

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

not-affected

hardy

DNE

intrepid

DNE

jaunty

DNE

karmic

not-affected

lucid

not-affected

maverick

not-affected

natty

not-affected

upstream

not-affected

Показывать по

EPSS

Процентиль: 19%
0.0006
Низкий

4.9 Medium

CVSS2

Связанные уязвимости

redhat
почти 17 лет назад

The kvm_arch_vcpu_ioctl_set_sregs function in the KVM in Linux kernel 2.6 before 2.6.30, when running on x86 systems, does not validate the page table root in a KVM_SET_SREGS call, which allows local users to cause a denial of service (crash or hang) via a crafted cr3 value, which triggers a NULL pointer dereference in the gfn_to_rmap function.

nvd
больше 16 лет назад

The kvm_arch_vcpu_ioctl_set_sregs function in the KVM in Linux kernel 2.6 before 2.6.30, when running on x86 systems, does not validate the page table root in a KVM_SET_SREGS call, which allows local users to cause a denial of service (crash or hang) via a crafted cr3 value, which triggers a NULL pointer dereference in the gfn_to_rmap function.

debian
больше 16 лет назад

The kvm_arch_vcpu_ioctl_set_sregs function in the KVM in Linux kernel ...

github
почти 4 года назад

The kvm_arch_vcpu_ioctl_set_sregs function in the KVM in Linux kernel 2.6 before 2.6.30, when running on x86 systems, does not validate the page table root in a KVM_SET_SREGS call, which allows local users to cause a denial of service (crash or hang) via a crafted cr3 value, which triggers a NULL pointer dereference in the gfn_to_rmap function.

EPSS

Процентиль: 19%
0.0006
Низкий

4.9 Medium

CVSS2

Уязвимость CVE-2009-2287