CVE-2010-2938
Summary
| CVE | CVE-2010-2938 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-10-08 21:00:02 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | arch/x86/hvm/vmx/vmcs.c in the virtual-machine control structure (VMCS) implementation in the Linux kernel 2.6.18 on Red Hat Enterprise Linux (RHEL) 5, when an Intel platform without Extended Page Tables (EPT) functionality is used, accesses VMCS fields without verifying hardware support for these fields, which allows local users to cause a denial of service (host OS crash) by requesting a VMCS dump for a fully virtualized Xen guest. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
NoneAvailability
CompleteAV:L/AC:L/Au:N/C:N/I:N/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Linux | Linux Kernel | 2.6.18 | All | All | All |
| Operating System | Redhat | Enterprise Linux | 5 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 620490 – (CVE-2010-2938) CVE-2010-2938 kernel: guest crashes on non-EPT machines may crash the host as well | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Linux Kernel Xen Hypervisor Implementation Denial of Service Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| xen-unstable.hg: log | af854a3a-2127-422b-91ae-364da2661108 | xenbits.xensource.com | |
| Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| About Secunia Research | Flexera | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| VMSA-2011-0012.2 | af854a3a-2127-422b-91ae-364da2661108 | www.vmware.com | |
| ASA-2010-291 (RHSA-2010-0723) | af854a3a-2127-422b-91ae-364da2661108 | support.avaya.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.