CVE-2010-0431

Severity
6.6MEDIUM
EPSS
0.1%
top 84.09%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 24
Latest updateMay 2

Description

QEMU-KVM, as used in the Hypervisor (aka rhev-hypervisor) in Red Hat Enterprise Virtualization (RHEV) 2.2 and KVM 83, does not properly validate guest QXL driver pointers, which allows guest OS users to cause a denial of service (invalid pointer dereference and guest OS crash) or possibly gain privileges via unspecified vectors.

CVSS vector

AV:L/AC:M/C:C/I:C/A:CExploitability: 2.7 | Impact: 10.0

Affected Packages2 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-6r53-qvwr-m586: QEMU-KVM, as used in the Hypervisor (aka rhev-hypervisor) in Red Hat Enterprise Virtualization (RHEV) 22022-05-02
CVEList
CVE-2010-0431: QEMU-KVM, as used in the Hypervisor (aka rhev-hypervisor) in Red Hat Enterprise Virtualization (RHEV) 22010-08-24

📋Vendor Advisories

1
Red Hat
qemu: Insufficient guest provided pointers validation2010-08-19

💬Community

1
Bugzilla
CVE-2010-0431 qemu: Insufficient guest provided pointers validation2010-02-26
CVE-2010-0431 (MEDIUM CVSS 6.6) | cvebase.io