Lucene search

K
prionPRIOn knowledge basePRION:CVE-2009-3640
HistoryOct 29, 2009 - 2:30 p.m.

Null pointer dereference

2009-10-2914:30:00
PRIOn knowledge base
www.prio-n.com
5

7.2 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

The update_cr8_intercept function in arch/x86/kvm/x86.c in the KVM subsystem in the Linux kernel before 2.6.32-rc1 does not properly handle the absence of an Advanced Programmable Interrupt Controller (APIC), which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly gain privileges via a call to the kvm_vcpu_ioctl function.

7.2 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%