CVE-2009-1242
published 2009-04-06CVE-2009-1242: The vmx_set_msr function in arch/x86/kvm/vmx.c in the VMX implementation in the KVM subsystem in the Linux kernel before 2.6.29.1 on the i386 platform allows…
PriorityP415medium4.9CVSS 2.0
AVLACLAuNCNINAC
EPSS
0.47%
37.8th percentile
The vmx_set_msr function in arch/x86/kvm/vmx.c in the VMX implementation in the KVM subsystem in the Linux kernel before 2.6.29.1 on the i386 platform allows guest OS users to cause a denial of service (OOPS) by setting the EFER_LME (aka "Long mode enable") bit in the Extended Feature Enable Register (EFER) model-specific register, which is specific to the x86_64 platform.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
| linux | linux_kernel | < 2.6.29.1 | 2.6.29.1 |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
CVSS provenance
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
vendor_redhat4.9MEDIUM
vendor_ubuntu4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wqvc-c395-66j7: The vmx_set_msr function in arch/x86/kvm/vmx
ghsa_unreviewed·2022-05-02
CVE-2009-1242 [MEDIUM] CWE-20 GHSA-wqvc-c395-66j7: The vmx_set_msr function in arch/x86/kvm/vmx
The vmx_set_msr function in arch/x86/kvm/vmx.c in the VMX implementation in the KVM subsystem in the Linux kernel before 2.6.29.1 on the i386 platform allows guest OS users to cause a denial of service (OOPS) by setting the EFER_LME (aka "Long mode enable") bit in the Extended Feature Enable Register (EFER) model-specific register, which is specific to the x86_64 platform.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2009-07-02·CVSS 4.9
CVE-2009-1242 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Linux kernel vulnerabilities
Igor Zhbanov discovered that NFS clients were able to create device nodes
even when root_squash was enabled. An authenticated remote attacker
could create device nodes with open permissions, leading to a loss of
privacy or escalation of privileges. Only Ubuntu 8.10 and 9.04 were
affected. (CVE-2009-1072)
Dan Carpenter discovered that SELinux did not correctly handle
certain network checks when running with compat_net=1. A local
attacker could exploit this to bypass network checks. Default Ubuntu
installations do not enable SELinux, and only Ubuntu 8.10 and 9.04 were
affected. (CVE-2009-1184)
Shaohua Li discovered that memory was not correctly initialized in the
AGP subsystem. A local attacker could potentially re
Red Hat
kernel: x86 guest OS can crash the system by writing to the EFER
vendor_redhat·2009-03-25·CVSS 4.9
CVE-2009-1242 [MEDIUM] kernel: x86 guest OS can crash the system by writing to the EFER
kernel: x86 guest OS can crash the system by writing to the EFER
The vmx_set_msr function in arch/x86/kvm/vmx.c in the VMX implementation in the KVM subsystem in the Linux kernel before 2.6.29.1 on the i386 platform allows guest OS users to cause a denial of service (OOPS) by setting the EFER_LME (aka "Long mode enable") bit in the Extended Feature Enable Register (EFER) model-specific register, which is specific to the x86_64 platform.
Statement: Not vulnerable. This issue did not affect the versions of Linux kernel as shipped with Red Hat Enterprise Linux 2.1, 3, 4, 5 or Red Hat Enterprise MRG.
No detection rules found.
No public exploits indexed.
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=16175a796d061833aacfbd9672235f2d2725df65http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-06/msg00002.htmlhttp://openwall.com/lists/oss-security/2009/04/01/3http://patchwork.kernel.org/patch/15549/http://secunia.com/advisories/34478http://secunia.com/advisories/34981http://secunia.com/advisories/35120http://secunia.com/advisories/35121http://secunia.com/advisories/35226http://secunia.com/advisories/35387http://secunia.com/advisories/35394http://secunia.com/advisories/35656http://vigilance.fr/vulnerability/Linux-kernel-denial-of-service-via-EFER-8585http://wiki.rpath.com/Advisories:rPSA-2009-0084http://www.debian.org/security/2009/dsa-1787http://www.debian.org/security/2009/dsa-1800http://www.globalsecuritymag.com/Vigil-nce-Linux-kernel-denial-of%2C20090402%2C8311http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.29.1http://www.kernel.org/pub/linux/kernel/v2.6/snapshots/patch-2.6.29-git1.loghttp://www.securityfocus.com/archive/1/503610/100/0/threadedhttp://www.securityfocus.com/bid/34331http://www.ubuntu.com/usn/usn-793-1http://www.vupen.com/english/advisories/2009/0924https://bugzilla.redhat.com/show_bug.cgi?id=502109https://exchange.xforce.ibmcloud.com/vulnerabilities/49594https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01126.htmlhttp://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=16175a796d061833aacfbd9672235f2d2725df65http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-06/msg00002.htmlhttp://openwall.com/lists/oss-security/2009/04/01/3http://patchwork.kernel.org/patch/15549/http://secunia.com/advisories/34478http://secunia.com/advisories/34981http://secunia.com/advisories/35120http://secunia.com/advisories/35121http://secunia.com/advisories/35226http://secunia.com/advisories/35387http://secunia.com/advisories/35394http://secunia.com/advisories/35656http://vigilance.fr/vulnerability/Linux-kernel-denial-of-service-via-EFER-8585http://wiki.rpath.com/Advisories:rPSA-2009-0084http://www.debian.org/security/2009/dsa-1787http://www.debian.org/security/2009/dsa-1800http://www.globalsecuritymag.com/Vigil-nce-Linux-kernel-denial-of%2C20090402%2C8311http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.29.1http://www.kernel.org/pub/linux/kernel/v2.6/snapshots/patch-2.6.29-git1.loghttp://www.securityfocus.com/archive/1/503610/100/0/threadedhttp://www.securityfocus.com/bid/34331http://www.ubuntu.com/usn/usn-793-1http://www.vupen.com/english/advisories/2009/0924https://bugzilla.redhat.com/show_bug.cgi?id=502109https://exchange.xforce.ibmcloud.com/vulnerabilities/49594https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01126.html
2009-04-06
Published