Executive Summary

Informations
Name CVE-2009-2287 First vendor Publication 2009-07-01
Vendor Cve Last vendor Modification 2023-11-07

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:L/AC:L/Au:N/C:N/I:N/A:C)
Cvss Base Score 4.9 Attack Range Local
Cvss Impact Score 6.9 Attack Complexity Low
Cvss Expoit Score 3.9 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

The kvm_arch_vcpu_ioctl_set_sregs function in the KVM in Linux kernel 2.6 before 2.6.30, when running on x86 systems, does not validate the page table root in a KVM_SET_SREGS call, which allows local users to cause a denial of service (crash or hang) via a crafted cr3 value, which triggers a NULL pointer dereference in the gfn_to_rmap function.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2287

CWE : Common Weakness Enumeration

% Id Name
100 % CWE-476 NULL Pointer Dereference

OVAL Definitions

Definition Id: oval:org.mitre.oval:def:13341
 
Oval ID: oval:org.mitre.oval:def:13341
Title: DSA-1846-1 kvm -- denial of service
Description: Matt T. Yourst discovered an issue in the kvm subsystem. Local users with permission to manipulate /dev/kvm can cause a denial of service by providing an invalid cr3 value to the KVM_SET_SREGS call. For the stable distribution, these problems have been fixed in version 72+dfsg-5~lenny2. For the unstable distribution, these problems will be fixed soon. We recommend that you upgrade your kvm packages, and rebuild any kernel modules you have built from a kvm-source package version.
Family: unix Class: patch
Reference(s): DSA-1846-1
CVE-2009-2287
Version: 5
Platform(s): Debian GNU/Linux 5.0
Product(s): kvm
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:7263
 
Oval ID: oval:org.mitre.oval:def:7263
Title: DSA-1846 kvm -- denial of service
Description: Matt T. Yourst discovered an issue in the kvm subsystem. Local users with permission to manipulate /dev/kvm can cause a denial of service (hang) by providing an invalid cr3 value to the KVM_SET_SREGS call.
Family: unix Class: patch
Reference(s): DSA-1846
CVE-2009-2287
Version: 3
Platform(s): Debian GNU/Linux 5.0
Product(s): kvm
Definition Synopsis:

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 1
Os 4
Os 2
Os 1138

OpenVAS Exploits

Date Description
2010-10-19 Name : Mandriva Update for kernel MDVSA-2010:198 (kernel)
File : nvt/gb_mandriva_MDVSA_2010_198.nasl
2010-09-27 Name : Mandriva Update for kernel MDVSA-2010:188 (kernel)
File : nvt/gb_mandriva_MDVSA_2010_188.nasl
2009-10-11 Name : SLES11: Security update for KVM
File : nvt/sles11_kvm.nasl
2009-08-17 Name : Debian Security Advisory DSA 1845-1 (linux-2.6)
File : nvt/deb_1845_1.nasl
2009-08-17 Name : Debian Security Advisory DSA 1846-1 (kvm)
File : nvt/deb_1846_1.nasl

Open Source Vulnerability Database (OSVDB)

Id Description
55567 Linux Kernel KVM on x86 kvm_arch_vcpu_ioctl_set_sregs Function Crafted CR3 Va...

Nessus® Vulnerability Scanner

Date Description
2010-10-08 Name : The remote Mandriva Linux host is missing one or more security updates.
File : mandriva_MDVSA-2010-198.nasl - Type : ACT_GATHER_INFO
2010-09-24 Name : The remote Mandriva Linux host is missing one or more security updates.
File : mandriva_MDVSA-2010-188.nasl - Type : ACT_GATHER_INFO
2010-02-24 Name : The remote Debian host is missing a security-related update.
File : debian_DSA-1845.nasl - Type : ACT_GATHER_INFO
2010-02-24 Name : The remote Debian host is missing a security-related update.
File : debian_DSA-1846.nasl - Type : ACT_GATHER_INFO
2009-09-24 Name : The remote SuSE 11 host is missing one or more security updates.
File : suse_11_kvm-090806.nasl - Type : ACT_GATHER_INFO
2009-07-29 Name : The remote Ubuntu host is missing one or more security-related patches.
File : ubuntu_USN-807-1.nasl - Type : ACT_GATHER_INFO

Sources (Detail)

http://git.kernel.org/?p=linux/kernel/git/stable/stable-queue.git%3Ba=blob%3B...
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commitdi...
Source Url
CONFIRM http://sourceforge.net/tracker/?func=detail&atid=893831&aid=2687641&a...
DEBIAN http://www.debian.org/security/2009/dsa-1845
MANDRIVA http://www.mandriva.com/security/advisories?name=MDVSA-2010:198
MLIST http://www.openwall.com/lists/oss-security/2009/06/30/1
SECUNIA http://secunia.com/advisories/35675
http://secunia.com/advisories/36045
http://secunia.com/advisories/36054
UBUNTU http://www.ubuntu.com/usn/usn-807-1

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
Date Informations
2024-02-02 01:11:17
  • Multiple Updates
2024-02-01 12:03:09
  • Multiple Updates
2023-11-07 21:47:42
  • Multiple Updates
2023-09-05 12:10:33
  • Multiple Updates
2023-09-05 01:03:00
  • Multiple Updates
2023-09-02 12:10:40
  • Multiple Updates
2023-09-02 01:03:01
  • Multiple Updates
2023-08-12 12:12:31
  • Multiple Updates
2023-08-12 01:03:00
  • Multiple Updates
2023-08-11 12:10:41
  • Multiple Updates
2023-08-11 01:03:08
  • Multiple Updates
2023-08-06 12:10:17
  • Multiple Updates
2023-08-06 01:03:02
  • Multiple Updates
2023-08-04 12:10:22
  • Multiple Updates
2023-08-04 01:03:04
  • Multiple Updates
2023-07-14 12:10:19
  • Multiple Updates
2023-07-14 01:03:02
  • Multiple Updates
2023-03-29 01:11:48
  • Multiple Updates
2023-03-28 12:03:08
  • Multiple Updates
2022-10-11 12:09:11
  • Multiple Updates
2022-10-11 01:02:51
  • Multiple Updates
2022-03-11 01:07:43
  • Multiple Updates
2021-05-04 12:10:07
  • Multiple Updates
2021-04-22 01:10:30
  • Multiple Updates
2020-09-03 01:04:44
  • Multiple Updates
2020-08-08 01:04:25
  • Multiple Updates
2020-08-01 12:04:28
  • Multiple Updates
2020-07-30 01:04:35
  • Multiple Updates
2020-05-23 01:40:35
  • Multiple Updates
2020-05-23 00:23:59
  • Multiple Updates
2019-01-25 12:02:48
  • Multiple Updates
2018-10-30 12:02:58
  • Multiple Updates
2016-08-05 12:02:09
  • Multiple Updates
2016-06-29 00:06:03
  • Multiple Updates
2016-06-28 17:44:56
  • Multiple Updates
2016-04-27 09:42:26
  • Multiple Updates
2016-04-26 18:56:21
  • Multiple Updates
2014-02-17 10:50:39
  • Multiple Updates
2013-05-10 23:53:19
  • Multiple Updates