{"api_version":"1","generated_at":"2026-07-23T11:41:14+00:00","cve":"CVE-2009-1758","urls":{"html":"https://cve.report/CVE-2009-1758","api":"https://cve.report/api/cve/CVE-2009-1758.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2009-1758","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2009-1758"},"summary":{"title":"CVE-2009-1758","description":"The hypervisor_callback function in Xen, possibly before 3.4.0, as applied to the Linux kernel 2.6.30-rc4, 2.6.18, and probably other versions allows guest user applications to cause a denial of service (kernel oops) of the guest OS by triggering a segmentation fault in \"certain address ranges.\"","state":"PUBLISHED","assigner":"mitre","published_at":"2009-05-22 11:52:40","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-399","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:P","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://lists.xensource.com/archives/html/xen-devel/2009-05/msg00561.html","name":"http://lists.xensource.com/archives/html/xen-devel/2009-05/msg00561.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"[Xen-devel] [PATCH] linux/i386: hypervisor_callback adjustments - Xen Source","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/34957","name":"http://www.securityfocus.com/bid/34957","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"504 Gateway Time-out","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://secunia.com/advisories/35093","name":"http://secunia.com/advisories/35093","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Xen \"hypervisor_callback()\" Denial of Service - Secunia Advisories - Vulnerability Information - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10313","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10313","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.openwall.com/lists/oss-security/2009/05/14/2","name":"http://www.openwall.com/lists/oss-security/2009/05/14/2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"oss-security - CVE Request: XEN local denial of service","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/35298","name":"http://secunia.com/advisories/35298","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Debian update for linux-2.6 - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.debian.org/security/2009/dsa-1809","name":"http://www.debian.org/security/2009/dsa-1809","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Debian -- Security Information -- DSA-1809-1 linux-2.6","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2009-1758","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2009-1758","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2009","cve_id":"1758","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"linux","cpe5":"linux_kernel","cpe6":"2.6.18","cpe7":"*","cpe8":"x86_32","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"1758","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"linux","cpe5":"linux_kernel","cpe6":"2.6.30","cpe7":"rc4","cpe8":"x86_32","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"1758","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"xen","cpe5":"xen","cpe6":"2.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"1758","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"xen","cpe5":"xen","cpe6":"3.0.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"1758","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"xen","cpe5":"xen","cpe6":"3.0.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"1758","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"xen","cpe5":"xen","cpe6":"3.0.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"1758","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"xen","cpe5":"xen","cpe6":"3.1.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"1758","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"xen","cpe5":"xen","cpe6":"3.1.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"1758","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"xen","cpe5":"xen","cpe6":"3.1.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"1758","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"xen","cpe5":"xen","cpe6":"3.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"1758","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"xen","cpe5":"xen","cpe6":"3.2.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"1758","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"xen","cpe5":"xen","cpe6":"3.2.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"1758","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"xen","cpe5":"xen","cpe6":"3.2.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"1758","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"xen","cpe5":"xen","cpe6":"3.2.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"1758","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"xen","cpe5":"xen","cpe6":"3.3.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"1758","vulnerable":"1","versionEndIncluding":"3.3.1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"xen","cpe5":"xen","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[{"cvename":"CVE-2009-1758","organization":"Red Hat","lastmodified":"2009-09-10","contributor":"Tomas Hoger","statementText":"This issue did not affect the versions of Linux kernel as shipped with Red Hat Enterprise Linux 2.1, 3, and Red Hat Enterprise MRG. It was addressed in Red Hat Enterprise Linux 4 and 5 via https://rhn.redhat.com/errata/RHSA-2009-1132.html and https://rhn.redhat.com/errata/RHSA-2009-1106.html .","cve_year":"2009","cve_id":"1758","crc32":"aaaf6cb5"}],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T05:27:53.667Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"35093","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/35093"},{"name":"[oss-security] 20090514 CVE Request: XEN local denial of service","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://www.openwall.com/lists/oss-security/2009/05/14/2"},{"name":"oval:org.mitre.oval:def:10313","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10313"},{"name":"35298","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/35298"},{"name":"34957","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/34957"},{"name":"[Xen-devel] 20090513 [PATCH] linux/i386: hypervisor_callback adjustments","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://lists.xensource.com/archives/html/xen-devel/2009-05/msg00561.html"},{"name":"DSA-1809","tags":["vendor-advisory","x_refsource_DEBIAN","x_transferred"],"url":"http://www.debian.org/security/2009/dsa-1809"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2009-05-14T00:00:00.000Z","descriptions":[{"lang":"en","value":"The hypervisor_callback function in Xen, possibly before 3.4.0, as applied to the Linux kernel 2.6.30-rc4, 2.6.18, and probably other versions allows guest user applications to cause a denial of service (kernel oops) of the guest OS by triggering a segmentation fault in \"certain address ranges.\""}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-09-28T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"35093","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/35093"},{"name":"[oss-security] 20090514 CVE Request: XEN local denial of service","tags":["mailing-list","x_refsource_MLIST"],"url":"http://www.openwall.com/lists/oss-security/2009/05/14/2"},{"name":"oval:org.mitre.oval:def:10313","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10313"},{"name":"35298","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/35298"},{"name":"34957","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/34957"},{"name":"[Xen-devel] 20090513 [PATCH] linux/i386: hypervisor_callback adjustments","tags":["mailing-list","x_refsource_MLIST"],"url":"http://lists.xensource.com/archives/html/xen-devel/2009-05/msg00561.html"},{"name":"DSA-1809","tags":["vendor-advisory","x_refsource_DEBIAN"],"url":"http://www.debian.org/security/2009/dsa-1809"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2009-1758","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The hypervisor_callback function in Xen, possibly before 3.4.0, as applied to the Linux kernel 2.6.30-rc4, 2.6.18, and probably other versions allows guest user applications to cause a denial of service (kernel oops) of the guest OS by triggering a segmentation fault in \"certain address ranges.\""}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"35093","refsource":"SECUNIA","url":"http://secunia.com/advisories/35093"},{"name":"[oss-security] 20090514 CVE Request: XEN local denial of service","refsource":"MLIST","url":"http://www.openwall.com/lists/oss-security/2009/05/14/2"},{"name":"oval:org.mitre.oval:def:10313","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10313"},{"name":"35298","refsource":"SECUNIA","url":"http://secunia.com/advisories/35298"},{"name":"34957","refsource":"BID","url":"http://www.securityfocus.com/bid/34957"},{"name":"[Xen-devel] 20090513 [PATCH] linux/i386: hypervisor_callback adjustments","refsource":"MLIST","url":"http://lists.xensource.com/archives/html/xen-devel/2009-05/msg00561.html"},{"name":"DSA-1809","refsource":"DEBIAN","url":"http://www.debian.org/security/2009/dsa-1809"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2009-1758","datePublished":"2009-05-22T01:00:00.000Z","dateReserved":"2009-05-21T00:00:00.000Z","dateUpdated":"2024-08-07T05:27:53.667Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2009-05-22 11:52:40","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-399","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:P","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":true,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:linux:linux_kernel:2.6.18:*:x86_32:*:*:*:*:*","matchCriteriaId":"A2B1B229-B325-4D8C-B326-1FF6D85891F5"},{"vulnerable":false,"criteria":"cpe:2.3:o:linux:linux_kernel:2.6.30:rc4:x86_32:*:*:*:*:*","matchCriteriaId":"06EFB3F7-2EAE-4A56-A9A1-E8C734E6B91E"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:xen:xen:*:*:*:*:*:*:*:*","versionEndIncluding":"3.3.1","matchCriteriaId":"07CFE66F-0105-42D4-80D5-427977D8757A"},{"vulnerable":true,"criteria":"cpe:2.3:a:xen:xen:2.0:*:*:*:*:*:*:*","matchCriteriaId":"A1A61248-160C-42F4-A803-20948FEA72CE"},{"vulnerable":true,"criteria":"cpe:2.3:a:xen:xen:3.0.2:*:*:*:*:*:*:*","matchCriteriaId":"FE0D9D45-1F2E-4236-858B-BBA54B17C8F5"},{"vulnerable":true,"criteria":"cpe:2.3:a:xen:xen:3.0.3:*:*:*:*:*:*:*","matchCriteriaId":"2AFDE72E-1997-48BA-A065-E0DD4ABE6E38"},{"vulnerable":true,"criteria":"cpe:2.3:a:xen:xen:3.0.4:*:*:*:*:*:*:*","matchCriteriaId":"A5E1D892-3A6C-4CC4-8237-231E593884EE"},{"vulnerable":true,"criteria":"cpe:2.3:a:xen:xen:3.1.2:*:*:*:*:*:*:*","matchCriteriaId":"D3C0C052-D6BA-4BC8-A64B-1A90CA572186"},{"vulnerable":true,"criteria":"cpe:2.3:a:xen:xen:3.1.3:*:*:*:*:*:*:*","matchCriteriaId":"54C61369-9EED-45CD-943C-DF26E818F09A"},{"vulnerable":true,"criteria":"cpe:2.3:a:xen:xen:3.1.4:*:*:*:*:*:*:*","matchCriteriaId":"D791DFF8-173B-49DB-AA8C-C1BBB8DB3611"},{"vulnerable":true,"criteria":"cpe:2.3:a:xen:xen:3.2:*:*:*:*:*:*:*","matchCriteriaId":"26281E48-3854-4C4B-8F71-2C2ED207F19C"},{"vulnerable":true,"criteria":"cpe:2.3:a:xen:xen:3.2.0:*:*:*:*:*:*:*","matchCriteriaId":"B242BA78-F752-414B-8DB9-D24E241EAE94"},{"vulnerable":true,"criteria":"cpe:2.3:a:xen:xen:3.2.1:*:*:*:*:*:*:*","matchCriteriaId":"717A9642-5033-47B1-B795-5676E950286B"},{"vulnerable":true,"criteria":"cpe:2.3:a:xen:xen:3.2.2:*:*:*:*:*:*:*","matchCriteriaId":"B0E18B3B-B562-49DF-AA75-13445B54CD1A"},{"vulnerable":true,"criteria":"cpe:2.3:a:xen:xen:3.2.3:*:*:*:*:*:*:*","matchCriteriaId":"3A9504C4-8826-40D8-823C-8E42F2453B9F"},{"vulnerable":true,"criteria":"cpe:2.3:a:xen:xen:3.3.0:*:*:*:*:*:*:*","matchCriteriaId":"92646AED-BF1E-4471-96A0-1926932AF4C8"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2009","CveId":"1758","Ordinal":"1","Title":"CVE-2009-1758","CVE":"CVE-2009-1758","Year":"2009"},"notes":[{"CveYear":"2009","CveId":"1758","Ordinal":"1","NoteData":"The hypervisor_callback function in Xen, possibly before 3.4.0, as applied to the Linux kernel 2.6.30-rc4, 2.6.18, and probably other versions allows guest user applications to cause a denial of service (kernel oops) of the guest OS by triggering a segmentation fault in \"certain address ranges.\"","Type":"Description","Title":"CVE-2009-1758"},{"CveYear":"2009","CveId":"1758","Ordinal":"2","NoteData":"2009-05-21","Type":"Other","Title":"Published"},{"CveYear":"2009","CveId":"1758","Ordinal":"3","NoteData":"2017-09-28","Type":"Other","Title":"Modified"}]}}}