Invoking ioctl(KVM_RUN) while having invalid selector in fs and/or gs register (via LDT modifications) forces kernel to panic (DoS).
Fixed in 2.6.36: http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=9581d442b9058d3699b4be568b6e5eae38a41493
This issue has been addressed in following products: Red Hat Enterprise Linux 6 Via RHSA-2010:0842 https://rhn.redhat.com/errata/RHSA-2010-0842.html
This issue has been addressed in following products: Red Hat Enterprise Linux 5 Via RHSA-2010:0898 https://rhn.redhat.com/errata/RHSA-2010-0898.html