CVE-2009-3722

Linux Kernel < 2.6.31 - Access Control

Title source: rule

Description

The handle_dr function in arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel before 2.6.31.1 does not properly verify the Current Privilege Level (CPL) before accessing a debug register, which allows guest OS users to cause a denial of service (trap) on the host OS via a crafted application.

Scores

EPSS 0.0260
EPSS Percentile 85.4%

Classification

CWE
CWE-264
Status draft

Affected Products (50)

linux/linux_kernel < 2.6.31
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
... and 35 more

Timeline

Published Oct 30, 2009
Tracked Since Feb 18, 2026