CVE-2009-4004

NameCVE-2009-4004
DescriptionBuffer overflow in the kvm_vcpu_ioctl_x86_setup_mce function in arch/x86/kvm/x86.c in the KVM subsystem in the Linux kernel before 2.6.32-rc7 allows local users to cause a denial of service (memory corruption) or possibly gain privileges via a KVM_X86_SETUP_MCE IOCTL request that specifies a large number of Machine Check Exception (MCE) banks.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs557736

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
kvmsourcelenny(not affected)
kvmsource(unstable)88+dfsg-2medium557736
linux-2.6sourceetch(not affected)
linux-2.6sourcelenny(not affected)
linux-2.6source(unstable)2.6.32-1medium
linux-2.6.24source(unstable)(not affected)

Notes

[etch] - linux-2.6 <not-affected> (kvm introduced in 2.6.25)
[lenny] - linux-2.6 <not-affected> (vulnerable code not present)
- linux-2.6.24 <not-affected> (kvm introduced in 2.6.25)
[lenny] - kvm <not-affected> (vulnerable code not present)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=a9e38c3e01ad242fe2a625354cf065c34b01e3aa

Search for package or bug name: Reporting problems