Lucene search

K
debiancveDebian Security Bug TrackerDEBIANCVE:CVE-2010-2938
HistoryOct 08, 2010 - 9:00 p.m.

CVE-2010-2938

2010-10-0821:00:02
Debian Security Bug Tracker
security-tracker.debian.org
13

4.9 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:N/I:N/A:C

0.0004 Low

EPSS

Percentile

5.1%

arch/x86/hvm/vmx/vmcs.c in the virtual-machine control structure (VMCS) implementation in the Linux kernel 2.6.18 on Red Hat Enterprise Linux (RHEL) 5, when an Intel platform without Extended Page Tables (EPT) functionality is used, accesses VMCS fields without verifying hardware support for these fields, which allows local users to cause a denial of service (host OS crash) by requesting a VMCS dump for a fully virtualized Xen guest.

OSVersionArchitecturePackageVersionFilename
Debian12allxen<ย 4.0.1-1xen_4.0.1-1_all.deb
Debian11allxen<ย 4.0.1-1xen_4.0.1-1_all.deb
Debian999allxen<ย 4.0.1-1xen_4.0.1-1_all.deb
Debian13allxen<ย 4.0.1-1xen_4.0.1-1_all.deb

4.9 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:N/I:N/A:C

0.0004 Low

EPSS

Percentile

5.1%