kernel: KVM: x86: check for cr3 validity in ioctl_set_sregs
Published Jul 1, 2009
4.9
MEDIUMCVSS 2.0
EPSS 0.40%
Description
The kvm_arch_vcpu_ioctl_set_sregs function in the KVM in Linux kernel 2.6 before 2.6.30, when running on x86 systems, does not validate the page table root in a KVM_SET_SREGS call, which allows local users to cause a denial of service (crash or hang) via a crafted cr3 value, which triggers a NULL pointer dereference in the gfn_to_rmap function.
Affected products
No data.
Configuration 1
- ≥ 2.6.0 · < 2.6.30
Configuration 2
- 6.06
- 8.04
- 8.10
- 9.04
Configuration 3
- 4.0
- 5.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Red Hat statement
Not vulnerable. This issue did not affect the versions of Linux kernel as shipped with Red Hat Enterprise Linux 3, 4, and 5, and Red Hat Enterprise MRG.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:L/AC:L/Au:N/C:N/I:N/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (9 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.40% (0.00398) | 31.56th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.40% (0.00398) | 31.33th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.05% (0.00048) | 12.17th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.04% (0.00042) | 5.07th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.04% (0.00042) | 5.63th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.28% (0.01282) | 68.34th | v2 (v2022.01.01) |
| Feb 22, 2023 | 1.28% (0.01282) | 68.05th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.28% (0.01282) | 65.91th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.28% (0.01282) | 41.72th | v2 (v2022.01.01) |
References (14)
- http://git.kernel.org/?p=linux/kernel/git/stable/stable-queue.git%3Ba=blob%3Bf=queue-2.6.30/kvm-x86-check-for-cr3-validity-in-ioctl_set_sregs.patch%3Bh=b48a47dad2cf76358b327368f80c0805e6370c68%3Bhb=e7c45b24f298b5d9efd7d401150f64a1b51aaac4 x_refsource_CONFIRM
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commitdiff%3Bh=59839dfff5eabca01cc4e20b45797a60a80af8cb x_refsource_CONFIRM
- http://secunia.com/advisories/35675 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/36045 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/36054 third-party-advisoryx_refsource_SECUNIABroken Link
- http://sourceforge.net/tracker/?func=detail&atid=893831&aid=2687641&group_id=180599 x_refsource_CONFIRMThird Party Advisory
- http://www.debian.org/security/2009/dsa-1845 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:198 vendor-advisoryx_refsource_MANDRIVABroken Link
- http://www.openwall.com/lists/oss-security/2009/06/30/1 mailing-listx_refsource_MLISTMailing ListPatchThird Party Advisory
- http://www.ubuntu.com/usn/usn-807-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2009-2287 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=512324 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2009-2287
- https://www.cve.org/CVERecord?id=CVE-2009-2287
Change history (0)
No recorded changes yet.