Bug 502109 - (CVE-2009-1242) CVE-2009-1242 kernel: x86 guest OS can crash the system by writing to the EFER
CVE-2009-1242 kernel: x86 guest OS can crash the system by writing to the EFER
Status: CLOSED ERRATA
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
http://cve.mitre.org/cgi-bin/cvename....
public=20090325,source=lkml,reported=...
: Security
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2009-05-21 18:26 EDT by Chuck Ebbert
Modified: 2012-03-28 04:35 EDT (History)
2 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2012-03-28 04:35:20 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Chuck Ebbert 2009-05-21 18:26:55 EDT
Description of problem:
The vmx_set_msr function in arch/x86/kvm/vmx.c in the VMX implementation in the KVM subsystem in the Linux kernel before 2.6.29.1 on the i386 platform allows guest OS users to cause a denial of service (OOPS) by setting the EFER_LME (aka "Long mode enable") bit in the Extended Feature Enable Register (EFER) model-specific register, which is specific to the x86_64 platform. 

Reference:
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff_plain;h=16175a796d061833aacfbd9672235f2d2725df65
Comment 1 Eugene Teo (Security Response) 2009-05-21 22:51:18 EDT
The bug was introduced in 6aa8b732ca (Dec 10, 2006).

This issue did not affect the versions of Linux kernel as shipped with Red Hat Enterprise Linux 2.1, 3, 4, 5 or Red Hat Enterprise MRG.

http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-1242
http://article.gmane.org/gmane.comp.security.oss.general/1606
Comment 2 Fedora Update System 2009-05-22 05:01:37 EDT
kernel-2.6.27.24-170.2.68.fc10 has been submitted as an update for Fedora 10.
http://admin.fedoraproject.org/updates/kernel-2.6.27.24-170.2.68.fc10
Comment 3 Fedora Update System 2009-05-25 17:09:15 EDT
kernel-2.6.27.24-170.2.68.fc10 has been pushed to the Fedora 10 stable repository.  If problems still persist, please make note of it in this bug report.

Note You need to log in before you can comment on or make changes to this bug.