Bug 502109 (CVE-2009-1242) - CVE-2009-1242 kernel: x86 guest OS can crash the system by writing to the EFER
Summary: CVE-2009-1242 kernel: x86 guest OS can crash the system by writing to the EFER
Alias: CVE-2009-1242
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL: http://cve.mitre.org/cgi-bin/cvename....
Whiteboard: public=20090325,source=lkml,reported=...
Keywords: Security
Depends On:
TreeView+ depends on / blocked
Reported: 2009-05-21 22:26 UTC by Chuck Ebbert
Modified: 2012-03-28 08:35 UTC (History)
2 users (show)

Clone Of:
Last Closed: 2012-03-28 08:35:20 UTC

Attachments (Terms of Use)

Description Chuck Ebbert 2009-05-21 22:26:55 UTC
Description of problem:
The vmx_set_msr function in arch/x86/kvm/vmx.c in the VMX implementation in the KVM subsystem in the Linux kernel before on the i386 platform allows guest OS users to cause a denial of service (OOPS) by setting the EFER_LME (aka "Long mode enable") bit in the Extended Feature Enable Register (EFER) model-specific register, which is specific to the x86_64 platform. 


Comment 1 Eugene Teo (Security Response) 2009-05-22 02:51:18 UTC
The bug was introduced in 6aa8b732ca (Dec 10, 2006).

This issue did not affect the versions of Linux kernel as shipped with Red Hat Enterprise Linux 2.1, 3, 4, 5 or Red Hat Enterprise MRG.


Comment 2 Fedora Update System 2009-05-22 09:01:37 UTC
kernel- has been submitted as an update for Fedora 10.

Comment 3 Fedora Update System 2009-05-25 21:09:15 UTC
kernel- has been pushed to the Fedora 10 stable repository.  If problems still persist, please make note of it in this bug report.

Note You need to log in before you can comment on or make changes to this bug.