Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 335872 (CVE-2010-0431) - app-emulation/{kvm-kmod,qemu-kvm}: multiple vulnerablites (CVE-2010-{0431,0435,2784})
Summary: app-emulation/{kvm-kmod,qemu-kvm}: multiple vulnerablites (CVE-2010-{0431,043...
Status: RESOLVED FIXED
Alias: CVE-2010-0431
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High trivial (vote)
Assignee: Gentoo Security
URL: https://bugzilla.redhat.com/show_bug....
Whiteboard: ~3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2010-09-03 20:54 UTC by Stefan Behte (RETIRED)
Modified: 2011-02-22 22:19 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Stefan Behte (RETIRED) gentoo-dev Security 2010-09-03 20:54:36 UTC
CVE-2010-0431 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-0431):
  QEMU-KVM, as used in the Hypervisor (aka rhev-hypervisor) in Red Hat
  Enterprise Virtualization (RHEV) 2.2 and KVM 83, does not properly
  validate guest QXL driver pointers, which allows guest OS users to
  cause a denial of service (invalid pointer dereference and guest OS
  crash) or possibly gain privileges via unspecified vectors.
Comment 1 Stefan Behte (RETIRED) gentoo-dev Security 2010-09-03 21:47:20 UTC
CVE-2010-0435 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-0435):
  The Hypervisor (aka rhev-hypervisor) in Red Hat Enterprise
  Virtualization (RHEV) 2.2, and KVM 83, when the Intel VT-x extension
  is enabled, allows guest OS users to cause a denial of service (NULL
  pointer dereference and host OS crash) via vectors related to
  instruction emulation.

CVE-2010-2784 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-2784):
  The subpage MMIO initialization functionality in the subpage_register
  function in exec.c in QEMU-KVM, as used in the Hypervisor (aka
  rhev-hypervisor) in Red Hat Enterprise Virtualization (RHEV) 2.2 and
  KVM 83, does not properly select the index for access to the callback
  array, which allows guest OS users to cause a denial of service
  (guest OS crash) or possibly gain privileges via unspecified vectors.

Comment 2 Jorge Manuel B. S. Vicetto (RETIRED) Gentoo Infrastructure gentoo-dev 2010-09-06 03:12:42 UTC
On a quick look at the referenced links, this seems to be all about kvm-83. If that's true, that version is no longer in the tree.
Comment 3 Doug Goldstein (RETIRED) gentoo-dev 2011-02-22 21:06:42 UTC
Yeah this has long been out of the Gentoo tree. Those versions were also never stable.
Comment 4 Stefan Behte (RETIRED) gentoo-dev Security 2011-02-22 22:19:17 UTC
Thanks for looking into it.