CVE-2010-2938
published 2010-10-08CVE-2010-2938: arch/x86/hvm/vmx/vmcs.c in the virtual-machine control structure (VMCS) implementation in the Linux kernel 2.6.18 on Red Hat Enterprise Linux (RHEL) 5, when an…
PriorityP414medium4.9CVSS 2.0
AVLACLAuNCNINAC
EPSS
0.35%
26.8th percentile
arch/x86/hvm/vmx/vmcs.c in the virtual-machine control structure (VMCS) implementation in the Linux kernel 2.6.18 on Red Hat Enterprise Linux (RHEL) 5, when an Intel platform without Extended Page Tables (EPT) functionality is used, accesses VMCS fields without verifying hardware support for these fields, which allows local users to cause a denial of service (host OS crash) by requesting a VMCS dump for a fully virtualized Xen guest.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xen | < xen 4.0.1-1 (bookworm) | xen 4.0.1-1 (bookworm) |
| linux | linux_kernel | — | — |
| vmware | vmware_esxi | — | — |
| vmware | vmware_workstation | — | — |
| vmware | vsphere | — | — |
| xen | xen | >= 0 < 4.0.1-1 | 4.0.1-1 |
| xen | xen | >= 0 < 4.0.1-1 | 4.0.1-1 |
| xen | xen | >= 0 < 4.0.1-1 | 4.0.1-1 |
| xen | xen | >= 0 < 4.0.1-1 | 4.0.1-1 |
CVSS provenance
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv4.9MEDIUM
vendor_debian4.9MEDIUM
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware ESX third party updates for Service Console packages glibc and dhcp
vendor_vmware·2011-10-12·CVSS 4.7
CVE-2010-0296 [MEDIUM] VMware ESX third party updates for Service Console packages glibc and dhcp
VMSA-2011-0012: VMware ESX third party updates for Service Console packages glibc and dhcp
a. ESX third party update for Service Console kernel This update takes the console OS kernel package to kernel-2.6.18-238.9.1 which resolves multiple security issues. The Common Vulnerabilities and Exposures project ( cve.mitre.org) has assigned the names CVE-2010-1083, CVE-2010-2492, CVE-2010-2798, CVE-2010-2938, CVE-2010-2942, CVE-2010-2943, CVE-2010-3015, CVE-2010-3066, CVE-2010-3067, CVE-2010-3078, CVE-2010-3086, CVE-2010-3296, CVE-2010-3432, CVE-2010-3442, CVE-2010-3477, CVE-2010-3699, CVE-2010-3858, CVE-2010-3859, CVE-2010-3865, CVE-2010-3876, CVE-2010-3877, CVE-2010-3880, CVE-2010-3904, CVE-2010-4072, CVE-2010-4073, CVE-2010-4075, CVE-2010-4080, CVE-2010-4081, CVE-2010-4083, CVE-2010-4157, CV
Red Hat
kernel: guest crashes on non-EPT machines may crash the host as well
vendor_redhat·2010-09-29·CVSS 4.9
CVE-2010-2938 [MEDIUM] kernel: guest crashes on non-EPT machines may crash the host as well
kernel: guest crashes on non-EPT machines may crash the host as well
arch/x86/hvm/vmx/vmcs.c in the virtual-machine control structure (VMCS) implementation in the Linux kernel 2.6.18 on Red Hat Enterprise Linux (RHEL) 5, when an Intel platform without Extended Page Tables (EPT) functionality is used, accesses VMCS fields without verifying hardware support for these fields, which allows local users to cause a denial of service (host OS crash) by requesting a VMCS dump for a fully virtualized Xen guest.
Debian
CVE-2010-2938: xen - arch/x86/hvm/vmx/vmcs.c in the virtual-machine control structure (VMCS) implemen...
vendor_debian·2010·CVSS 4.9
CVE-2010-2938 [MEDIUM] CVE-2010-2938: xen - arch/x86/hvm/vmx/vmcs.c in the virtual-machine control structure (VMCS) implemen...
arch/x86/hvm/vmx/vmcs.c in the virtual-machine control structure (VMCS) implementation in the Linux kernel 2.6.18 on Red Hat Enterprise Linux (RHEL) 5, when an Intel platform without Extended Page Tables (EPT) functionality is used, accesses VMCS fields without verifying hardware support for these fields, which allows local users to cause a denial of service (host OS crash) by requesting a VMCS dump for a fully virtualized Xen guest.
Scope: local
bookworm: resolved (fixed in 4.0.1-1)
bullseye: resolved (fixed in 4.0.1-1)
forky: resolved (fixed in 4.0.1-1)
sid: resolved (fixed in 4.0.1-1)
trixie: resolved (fixed in 4.0.1-1)
GHSA
GHSA-9cjj-33q2-5pjr: arch/x86/hvm/vmx/vmcs
ghsa_unreviewed·2022-05-14
CVE-2010-2938 [MEDIUM] GHSA-9cjj-33q2-5pjr: arch/x86/hvm/vmx/vmcs
arch/x86/hvm/vmx/vmcs.c in the virtual-machine control structure (VMCS) implementation in the Linux kernel 2.6.18 on Red Hat Enterprise Linux (RHEL) 5, when an Intel platform without Extended Page Tables (EPT) functionality is used, accesses VMCS fields without verifying hardware support for these fields, which allows local users to cause a denial of service (host OS crash) by requesting a VMCS dump for a fully virtualized Xen guest.
OSV
CVE-2010-2938: arch/x86/hvm/vmx/vmcs
osv·2010-10-08·CVSS 4.9
CVE-2010-2938 [MEDIUM] CVE-2010-2938: arch/x86/hvm/vmx/vmcs
arch/x86/hvm/vmx/vmcs.c in the virtual-machine control structure (VMCS) implementation in the Linux kernel 2.6.18 on Red Hat Enterprise Linux (RHEL) 5, when an Intel platform without Extended Page Tables (EPT) functionality is used, accesses VMCS fields without verifying hardware support for these fields, which allows local users to cause a denial of service (host OS crash) by requesting a VMCS dump for a fully virtualized Xen guest.
No detection rules found.
No public exploits indexed.
http://secunia.com/advisories/46397http://support.avaya.com/css/P8/documents/100113326http://www.redhat.com/support/errata/RHSA-2010-0723.htmlhttp://www.securityfocus.com/archive/1/520102/100/0/threadedhttp://www.securityfocus.com/bid/43578http://www.vmware.com/security/advisories/VMSA-2011-0012.htmlhttp://xenbits.xensource.com/xen-unstable.hg?rev/15911https://bugzilla.redhat.com/show_bug.cgi?id=620490http://secunia.com/advisories/46397http://support.avaya.com/css/P8/documents/100113326http://www.redhat.com/support/errata/RHSA-2010-0723.htmlhttp://www.securityfocus.com/archive/1/520102/100/0/threadedhttp://www.securityfocus.com/bid/43578http://www.vmware.com/security/advisories/VMSA-2011-0012.htmlhttp://xenbits.xensource.com/xen-unstable.hg?rev/15911https://bugzilla.redhat.com/show_bug.cgi?id=620490
2010-10-08
Published