cbcvebase.
CVE-2010-2938
published 2010-10-08

CVE-2010-2938: arch/x86/hvm/vmx/vmcs.c in the virtual-machine control structure (VMCS) implementation in the Linux kernel 2.6.18 on Red Hat Enterprise Linux (RHEL) 5, when an…

PriorityP414medium4.9CVSS 2.0
AVLACLAuNCNINAC
EPSS
0.35%
26.8th percentile
arch/x86/hvm/vmx/vmcs.c in the virtual-machine control structure (VMCS) implementation in the Linux kernel 2.6.18 on Red Hat Enterprise Linux (RHEL) 5, when an Intel platform without Extended Page Tables (EPT) functionality is used, accesses VMCS fields without verifying hardware support for these fields, which allows local users to cause a denial of service (host OS crash) by requesting a VMCS dump for a fully virtualized Xen guest.

Affected

9 ranges
VendorProductVersion rangeFixed in
debianxen< xen 4.0.1-1 (bookworm)xen 4.0.1-1 (bookworm)
linuxlinux_kernel
vmwarevmware_esxi
vmwarevmware_workstation
vmwarevsphere
xenxen>= 0 < 4.0.1-14.0.1-1
xenxen>= 0 < 4.0.1-14.0.1-1
xenxen>= 0 < 4.0.1-14.0.1-1
xenxen>= 0 < 4.0.1-14.0.1-1

CVSS provenance

nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv4.9MEDIUM
vendor_debian4.9MEDIUM
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.