CVE-2009-3638

Linux Kernel < 2.6.31.3 - Numeric Error

Title source: rule

Description

Integer overflow in the kvm_dev_ioctl_get_supported_cpuid function in arch/x86/kvm/x86.c in the KVM subsystem in the Linux kernel before 2.6.31.4 allows local users to have an unspecified impact via a KVM_GET_SUPPORTED_CPUID request to the kvm_arch_dev_ioctl function.

Scores

EPSS 0.0006
EPSS Percentile 17.6%

Classification

CWE
CWE-189
Status draft

Affected Products (50)

linux/linux_kernel < 2.6.31.3
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
... and 35 more

Timeline

Published Oct 29, 2009
Tracked Since Feb 18, 2026