Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 531660 - (CVE-2009-3722) CVE-2009-3722 KVM: Check cpl before emulating debug register access
CVE-2009-3722 KVM: Check cpl before emulating debug register access
Status: CLOSED ERRATA
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
medium Severity medium
: ---
: ---
Assigned To: Karen Noel
impact=moderate,reported=20091029,pub...
: Reopened, Security
Depends On: 531661 563516 563517 563934
Blocks:
  Show dependency treegraph
 
Reported: 2009-10-28 23:09 EDT by Eugene Teo (Security Response)
Modified: 2013-01-09 06:28 EST (History)
8 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2011-04-20 08:18:55 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2010:0126 normal SHIPPED_LIVE Important: kvm security and bug fix update 2010-03-01 14:23:38 EST
Red Hat Product Errata RHSA-2010:0172 normal SHIPPED_LIVE Important: rhev-hypervisor security and bug fix update 2010-03-24 11:46:46 EDT

  None (edit)
Description Eugene Teo (Security Response) 2009-10-28 23:09:31 EDT
Quote from the upstream commit:
Debug registers may only be accessed from cpl 0.  Unfortunately, vmx will code to emulate the instruction even though it was issued from guest userspace, possibly leading to an unexpected trap later.

Introduced in v2.6.30-rc1; Fixed in v2.6.32-rc1.

http://git.kernel.org/linus/0a79b009525b160081d75cef5dbf45817956acf2
Comment 3 Eugene Teo (Security Response) 2009-10-28 23:22:20 EDT
None of our kernels is affected by this vulnerability. Closing this bug as NOTABUG.
Comment 4 Chuck Ebbert 2009-10-29 07:29:06 EDT
Also fixed in 2.6.30.9 and 2.6.31.1
Comment 5 Avi Kivity 2010-02-10 08:35:13 EST
The kvm package in RHEL 5.[45] is in fact vulnerable.
Comment 9 errata-xmlrpc 2010-03-01 14:23:50 EST
This issue has been addressed in following products:

  Red Hat Enterprise Linux 5

Via RHSA-2010:0126 https://rhn.redhat.com/errata/RHSA-2010-0126.html
Comment 10 errata-xmlrpc 2010-03-24 11:47:02 EDT
This issue has been addressed in following products:

  Red Hat Enterprise Virtualization for RHEL-5

Via RHSA-2010:0172 https://rhn.redhat.com/errata/RHSA-2010-0172.html
Comment 11 Avi Kivity 2010-12-22 04:55:42 EST
Should this bug be closed?

Note You need to log in before you can comment on or make changes to this bug.