Back

MEDIUM

kvm: emulator privilege escalation

Published Feb 12, 2010

Description

The x86 emulator in KVM 83 does not use the Current Privilege Level (CPL) and I/O Privilege Level (IOPL) in determining the memory access available to CPL3 code, which allows guest OS users to cause a denial of service (guest OS crash) or gain privileges on the guest OS by leveraging access to a (1) IO port or (2) MMIO region, a related issue to CVE-2010-0306.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Feb 12, 2010
Updated Aug 7, 2024
Reserved Jan 12, 2010
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Important
Public date Feb 9, 2010