Name | CVE-2009-4004 |
Description | Buffer overflow in the kvm_vcpu_ioctl_x86_setup_mce function in arch/x86/kvm/x86.c in the KVM subsystem in the Linux kernel before 2.6.32-rc7 allows local users to cause a denial of service (memory corruption) or possibly gain privileges via a KVM_X86_SETUP_MCE IOCTL request that specifies a large number of Machine Check Exception (MCE) banks. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
Debian Bugs | 557736 |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
kvm | source | lenny | (not affected) | |||
kvm | source | (unstable) | 88+dfsg-2 | medium | 557736 | |
linux-2.6 | source | etch | (not affected) | |||
linux-2.6 | source | lenny | (not affected) | |||
linux-2.6 | source | (unstable) | 2.6.32-1 | medium | ||
linux-2.6.24 | source | (unstable) | (not affected) |
[etch] - linux-2.6 <not-affected> (kvm introduced in 2.6.25)
[lenny] - linux-2.6 <not-affected> (vulnerable code not present)
- linux-2.6.24 <not-affected> (kvm introduced in 2.6.25)
[lenny] - kvm <not-affected> (vulnerable code not present)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=a9e38c3e01ad242fe2a625354cf065c34b01e3aa