CVE-2010-2938
Linux kernel 2.6.18 on RHEL 5 - Denial of Service via VMCS Dump Request
Title source: llmDescription
arch/x86/hvm/vmx/vmcs.c in the virtual-machine control structure (VMCS) implementation in the Linux kernel 2.6.18 on Red Hat Enterprise Linux (RHEL) 5, when an Intel platform without Extended Page Tables (EPT) functionality is used, accesses VMCS fields without verifying hardware support for these fields, which allows local users to cause a denial of service (host OS crash) by requesting a VMCS dump for a fully virtualized Xen guest.
References (8)
Core 8
Core References
Vendor Advisory vendor-advisory
x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2010-0723.html
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/520102/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/43578
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/46397
Various Sources x_refsource_confirm
http://xenbits.xensource.com/xen-unstable.hg?rev/15911
Vendor Advisory x_refsource_confirm
http://www.vmware.com/security/advisories/VMSA-2011-0012.html
Vendor Advisory x_refsource_confirm
http://support.avaya.com/css/P8/documents/100113326
Issue Tracking x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=620490
Scores
EPSS
0.0035
EPSS Percentile
27.3%
Details
CWE
CWE-399
Status
published
Products (1)
linux/linux_kernel
2.6.18
Published
Oct 08, 2010
Tracked Since
Feb 18, 2026