LWN.net Logo

kvm: host denial of service

Package(s):kvm CVE #(s):CVE-2009-4031
Created:December 9, 2009 Updated:March 22, 2010
Description:

From the Red Hat advisory:

On x86 platforms, the do_insn_fetch() function did not limit the amount of instruction bytes fetched per instruction. Users in guest operating systems could leverage this flaw to cause large latencies on SMP hosts that could lead to a local denial of service on the host operating system. This update fixes this issue by imposing the architecturally-defined 15 byte length limit for instructions. (CVE-2009-4031)

Alerts:
SuSE SUSE-SA:2010:018 2010-03-22
Ubuntu USN-894-1 2010-02-05
Debian DSA-1962 2009-12-23
CentOS CESA-2009:1659 2009-12-18
Fedora FEDORA-2009-13098 2009-12-11
Red Hat RHSA-2009:1659-01 2009-12-09

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds