6.8
CVSSv2

CVE-2010-0309

Published: 12/02/2010 Updated: 13/02/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.9 | Exploitability Score: 8
VMScore: 605
Vector: AV:N/AC:L/Au:S/C:N/I:N/A:C

Vulnerability Summary

The pit_ioport_read function in the Programmable Interval Timer (PIT) emulation in i8254.c in KVM 83 does not properly use the pit_state data structure, which allows guest OS users to cause a denial of service (host OS crash or hang) by attempting to read the /dev/port file.

Vulnerable Product Search on Vulmon Subscribe to Product

linux kernel

Vendor Advisories

Synopsis Important: kvm security and bug fix update Type/Severity Security Advisory: Important Topic Updated kvm packages that fix multiple security issues and several bugs arenow available for Red Hat Enterprise Linux 5This update has been rated as having important security impact by the RedHat Security R ...
Mathias Krause discovered that the Linux kernel did not correctly handle missing ELF interpreters A local attacker could exploit this to cause the system to crash, leading to a denial of service (CVE-2010-0307) ...
Several local vulnerabilities have been discovered in kvm, a full virtualization system The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2010-0298 CVE-2010-0306 Gleb Natapov discovered issues in the KVM subsystem where missing permission checks (CPL/IOPL) permit a user in a guest system to de ...