KVM Block Device Backend Local Security Bypass Vulnerability
BID:28001
Info
KVM Block Device Backend Local Security Bypass Vulnerability
| Bugtraq ID: | 28001 |
| Class: | Access Validation Error |
| CVE: |
CVE-2008-0928 |
| Remote: | No |
| Local: | Yes |
| Published: | Feb 26 2008 12:00AM |
| Updated: | Apr 16 2015 05:49PM |
| Credit: | Ian Jackson is credited with discovering this issue. |
| Vulnerable: |
SuSE SUSE Linux Enterprise Server 11 SuSE SUSE Linux Enterprise Server 10 SuSE openSUSE 10.3 S.u.S.E. openSUSE 11.1 S.u.S.E. openSUSE 11.0 Red Hat Fedora 7 Qumranet KVM 36 Pardus Linux 2008 0 Debian Linux 5.0 sparc Debian Linux 5.0 s/390 Debian Linux 5.0 powerpc Debian Linux 5.0 mipsel Debian Linux 5.0 mips Debian Linux 5.0 m68k Debian Linux 5.0 ia-64 Debian Linux 5.0 ia-32 Debian Linux 5.0 hppa Debian Linux 5.0 armel Debian Linux 5.0 arm Debian Linux 5.0 amd64 Debian Linux 5.0 alpha Debian Linux 5.0 Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 armel Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 |
| Not Vulnerable: | |
Discussion
KVM Block Device Backend Local Security Bypass Vulnerability
KVM (Kernel-based Virtual Machine) is prone to a local security-bypass vulnerability because it fails to validate user-supplied input.
Local attackers can leverage this issue to access memory outside of the virtualization jail. This could allow attackers to write to arbitrary host memory locations or crash the underlying KVM host. Other attacks may also be possible.
KVM (Kernel-based Virtual Machine) is prone to a local security-bypass vulnerability because it fails to validate user-supplied input.
Local attackers can leverage this issue to access memory outside of the virtualization jail. This could allow attackers to write to arbitrary host memory locations or crash the underlying KVM host. Other attacks may also be possible.
Exploit / POC
KVM Block Device Backend Local Security Bypass Vulnerability
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
KVM Block Device Backend Local Security Bypass Vulnerability
Solution:
Updates are available. Please see the references for more information.
Debian Linux 5.0 ia-32
Debian Linux 4.0 amd64
Debian Linux 4.0 ia-32
Debian Linux 5.0 amd64
Debian Linux 5.0 powerpc
Debian Linux 5.0 sparc
Solution:
Updates are available. Please see the references for more information.
Debian Linux 5.0 ia-32
-
Debian qemu_0.9.1-10lenny1_i386.deb
http://security.debian.org/pool/updates/main/q/qemu/qemu_0.9.1-10lenny 1_i386.deb
Debian Linux 4.0 amd64
-
Debian qemu_0.8.2-4etch3_amd64.deb
http://security.debian.org/pool/updates/main/q/qemu/qemu_0.8.2-4etch3_ amd64.deb
Debian Linux 4.0 ia-32
-
Debian qemu_0.8.2-4etch3_i386.deb
http://security.debian.org/pool/updates/main/q/qemu/qemu_0.8.2-4etch3_ i386.deb
Debian Linux 5.0 amd64
-
Debian qemu_0.9.1-10lenny1_amd64.deb
http://security.debian.org/pool/updates/main/q/qemu/qemu_0.9.1-10lenny 1_amd64.deb
Debian Linux 5.0 powerpc
-
Debian qemu_0.9.1-10lenny1_powerpc.deb
http://security.debian.org/pool/updates/main/q/qemu/qemu_0.9.1-10lenny 1_powerpc.deb
Debian Linux 5.0 sparc
-
Debian qemu_0.9.1-10lenny1_sparc.deb
http://security.debian.org/pool/updates/main/q/qemu/qemu_0.9.1-10lenny 1_sparc.deb
References
KVM Block Device Backend Local Security Bypass Vulnerability
References:
References:
- KVM Homepage (Qumranet)
- qemu unchecked block read/write vulnerability (Ian Jackson)
- FEDORA-2008-1973 Fedora 7 Update: kvm-36-8.fc7 (Red Hat)
- FEDORA-2008-1993 Fedora 8 Update: kvm-60-2.fc8 (Red Hat)