CVE-2010-5313
published 2014-11-30CVE-2010-5313: Race condition in arch/x86/kvm/x86.c in the Linux kernel before 2.6.38 allows L2 guest OS users to cause a denial of service (L1 guest OS crash) via a crafted…
PriorityP417medium4.9CVSS 2.0
AVLACLAuNCNINAC
EPSS
0.33%
25.1th percentile
Race condition in arch/x86/kvm/x86.c in the Linux kernel before 2.6.38 allows L2 guest OS users to cause a denial of service (L1 guest OS crash) via a crafted instruction that triggers an L2 emulation failure report, a similar issue to CVE-2014-7842.
Affected
185 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 2.6.38-1 (bookworm) | linux 2.6.38-1 (bookworm) |
| debian | linux | < linux 3.16.7-ckt2-1 (bookworm) | linux 3.16.7-ckt2-1 (bookworm) |
| linux | linux_kernel | <= 2.6.37 | — |
| linux | linux_kernel | <= 3.17.3 | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
CVSS provenance
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv4.9MEDIUM
vendor_debian4.9MEDIUM
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: kvm: reporting emulation failures to userspace
vendor_redhat·2014-09-24·CVSS 4.9
CVE-2014-7842 [MEDIUM] kernel: kvm: reporting emulation failures to userspace
kernel: kvm: reporting emulation failures to userspace
Race condition in arch/x86/kvm/x86.c in the Linux kernel before 3.17.4 allows guest OS users to cause a denial of service (guest OS crash) via a crafted application that performs an MMIO transaction or a PIO transaction to trigger a guest userspace emulation error report, a similar issue to CVE-2010-5313.
It was found that reporting emulation failures to user space could lead to either a local (CVE-2014-7842) or a L2->L1 (CVE-2010-5313) denial of service. In the case of a local denial of service, an attacker must have access to the MMIO area or be able to access an I/O port. Please note that on certain systems, HPET is mapped to userspace as part of vdso (vvar) and thus an unprivileged user may generate MMIO transactions (and enter t
Red Hat
kernel: kvm: reporting emulation failures to userspace
vendor_redhat·2014-09-24·CVSS 4.9
CVE-2010-5313 [MEDIUM] kernel: kvm: reporting emulation failures to userspace
kernel: kvm: reporting emulation failures to userspace
Race condition in arch/x86/kvm/x86.c in the Linux kernel before 2.6.38 allows L2 guest OS users to cause a denial of service (L1 guest OS crash) via a crafted instruction that triggers an L2 emulation failure report, a similar issue to CVE-2014-7842.
It was found that reporting emulation failures to user space could lead to either a local (CVE-2014-7842) or a L2->L1 (CVE-2010-5313) denial of service. In the case of a local denial of service, an attacker must have access to the MMIO area or be able to access an I/O port. Please note that on certain systems, HPET is mapped to userspace as part of vdso (vvar) and thus an unprivileged user may generate MMIO transactions (and enter the emulator) this way.
Statement: This issue did not af
Debian
CVE-2014-7842: linux - Race condition in arch/x86/kvm/x86.c in the Linux kernel before 3.17.4 allows gu...
vendor_debian·2014·CVSS 4.9
CVE-2014-7842 [MEDIUM] CVE-2014-7842: linux - Race condition in arch/x86/kvm/x86.c in the Linux kernel before 3.17.4 allows gu...
Race condition in arch/x86/kvm/x86.c in the Linux kernel before 3.17.4 allows guest OS users to cause a denial of service (guest OS crash) via a crafted application that performs an MMIO transaction or a PIO transaction to trigger a guest userspace emulation error report, a similar issue to CVE-2010-5313.
Scope: local
bookworm: resolved (fixed in 3.16.7-ckt2-1)
bullseye: resolved (fixed in 3.16.7-ckt2-1)
forky: resolved (fixed in 3.16.7-ckt2-1)
sid: resolved (fixed in 3.16.7-ckt2-1)
trixie: resolved (fixed in 3.16.7-ckt2-1)
Debian
CVE-2010-5313: linux - Race condition in arch/x86/kvm/x86.c in the Linux kernel before 2.6.38 allows L2...
vendor_debian·2010·CVSS 4.9
CVE-2010-5313 [MEDIUM] CVE-2010-5313: linux - Race condition in arch/x86/kvm/x86.c in the Linux kernel before 2.6.38 allows L2...
Race condition in arch/x86/kvm/x86.c in the Linux kernel before 2.6.38 allows L2 guest OS users to cause a denial of service (L1 guest OS crash) via a crafted instruction that triggers an L2 emulation failure report, a similar issue to CVE-2014-7842.
Scope: local
bookworm: resolved (fixed in 2.6.38-1)
bullseye: resolved (fixed in 2.6.38-1)
forky: resolved (fixed in 2.6.38-1)
sid: resolved (fixed in 2.6.38-1)
trixie: resolved (fixed in 2.6.38-1)
GHSA
GHSA-8hgg-pmrm-w85w: Race condition in arch/x86/kvm/x86
ghsa_unreviewed·2022-05-17·CVSS 4.9
CVE-2010-5313 [MEDIUM] CWE-362 GHSA-8hgg-pmrm-w85w: Race condition in arch/x86/kvm/x86
Race condition in arch/x86/kvm/x86.c in the Linux kernel before 2.6.38 allows L2 guest OS users to cause a denial of service (L1 guest OS crash) via a crafted instruction that triggers an L2 emulation failure report, a similar issue to CVE-2014-7842.
GHSA
GHSA-5j6g-rhrc-x47f: Race condition in arch/x86/kvm/x86
ghsa_unreviewed·2022-05-17·CVSS 4.9
CVE-2014-7842 [MEDIUM] CWE-362 GHSA-5j6g-rhrc-x47f: Race condition in arch/x86/kvm/x86
Race condition in arch/x86/kvm/x86.c in the Linux kernel before 3.17.4 allows guest OS users to cause a denial of service (guest OS crash) via a crafted application that performs an MMIO transaction or a PIO transaction to trigger a guest userspace emulation error report, a similar issue to CVE-2010-5313.
OSV
CVE-2014-7842: Race condition in arch/x86/kvm/x86
osv·2014-11-30·CVSS 4.9
CVE-2014-7842 [MEDIUM] CVE-2014-7842: Race condition in arch/x86/kvm/x86
Race condition in arch/x86/kvm/x86.c in the Linux kernel before 3.17.4 allows guest OS users to cause a denial of service (guest OS crash) via a crafted application that performs an MMIO transaction or a PIO transaction to trigger a guest userspace emulation error report, a similar issue to CVE-2010-5313.
OSV
CVE-2010-5313: Race condition in arch/x86/kvm/x86
osv·2014-11-30·CVSS 4.9
CVE-2010-5313 [MEDIUM] CVE-2010-5313: Race condition in arch/x86/kvm/x86
Race condition in arch/x86/kvm/x86.c in the Linux kernel before 2.6.38 allows L2 guest OS users to cause a denial of service (L1 guest OS crash) via a crafted instruction that triggers an L2 emulation failure report, a similar issue to CVE-2014-7842.
No detection rules found.
No public exploits indexed.
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=fc3a9157d3148ab91039c75423da8ef97be3e105http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00000.htmlhttp://mirror.linux.org.au/linux/kernel/v2.6/ChangeLog-2.6.38http://rhn.redhat.com/errata/RHSA-2016-0855.htmlhttp://www.openwall.com/lists/oss-security/2014/11/13/7http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/71363https://bugzilla.redhat.com/show_bug.cgi?id=1163762https://github.com/torvalds/linux/commit/fc3a9157d3148ab91039c75423da8ef97be3e105http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=fc3a9157d3148ab91039c75423da8ef97be3e105http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00000.htmlhttp://mirror.linux.org.au/linux/kernel/v2.6/ChangeLog-2.6.38http://rhn.redhat.com/errata/RHSA-2016-0855.htmlhttp://www.openwall.com/lists/oss-security/2014/11/13/7http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/71363https://bugzilla.redhat.com/show_bug.cgi?id=1163762https://github.com/torvalds/linux/commit/fc3a9157d3148ab91039c75423da8ef97be3e105
2014-11-30
Published