SB2009112002 - Buffer overflow in Linux kernel x86 kvm
Published: November 20, 2009
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Buffer overflow (CVE-ID: CVE-2009-4004)
The vulnerability allows a local user to execute arbitrary code.
The vulnerability exists due to memory corruption within the kvm_vcpu_ioctl_x86_setup_mce() function in arch/x86/kvm/x86.c. A local user can execute arbitrary code.
Remediation
Install update from vendor's website.
References
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=a9e38c3e01ad242fe2a625354cf065c34b01e3aa
- http://secunia.com/advisories/37357
- http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.32-rc7
- http://www.securityfocus.com/bid/37035
- http://www.vupen.com/english/advisories/2009/3267
- https://exchange.xforce.ibmcloud.com/vulnerabilities/54302