CVE-2009-1758
Summary
| CVE | CVE-2009-1758 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-05-22 11:52:40 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | The hypervisor_callback function in Xen, possibly before 3.4.0, as applied to the Linux kernel 2.6.30-rc4, 2.6.18, and probably other versions allows guest user applications to cause a denial of service (kernel oops) of the guest OS by triggering a segmentation fault in "certain address ranges." |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
NoneAvailability
PartialAV:N/AC:L/Au:N/C:N/I:N/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Linux | Linux Kernel | 2.6.18 | All | x86_32 | All |
| Operating System | Linux | Linux Kernel | 2.6.30 | rc4 | x86_32 | All |
| Application | Xen | Xen | 2.0 | All | All | All |
| Application | Xen | Xen | 3.0.2 | All | All | All |
| Application | Xen | Xen | 3.0.3 | All | All | All |
| Application | Xen | Xen | 3.0.4 | All | All | All |
| Application | Xen | Xen | 3.1.2 | All | All | All |
| Application | Xen | Xen | 3.1.3 | All | All | All |
| Application | Xen | Xen | 3.1.4 | All | All | All |
| Application | Xen | Xen | 3.2 | All | All | All |
| Application | Xen | Xen | 3.2.0 | All | All | All |
| Application | Xen | Xen | 3.2.1 | All | All | All |
| Application | Xen | Xen | 3.2.2 | All | All | All |
| Application | Xen | Xen | 3.2.3 | All | All | All |
| Application | Xen | Xen | 3.3.0 | All | All | All |
| Application | Xen | Xen | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [Xen-devel] [PATCH] linux/i386: hypervisor_callback adjustments - Xen Source | af854a3a-2127-422b-91ae-364da2661108 | lists.xensource.com | Exploit |
| 504 Gateway Time-out | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Xen "hypervisor_callback()" Denial of Service - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| oss-security - CVE Request: XEN local denial of service | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| Debian update for linux-2.6 - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Debian -- Security Information -- DSA-1809-1 linux-2.6 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Red Hat | 2009-09-10 | Tomas Hoger | This issue did not affect the versions of Linux kernel as shipped with Red Hat Enterprise Linux 2.1, 3, and Red Hat Enterprise MRG. It was addressed in Red Hat Enterprise Linux 4 and 5 via https://rhn.redhat.com/errata/RHSA-2009-1132.html and https://rhn.redhat.com/errata/RHSA-2009-1106.html . |
There are currently no legacy QID mappings associated with this CVE.