First published: Tue Apr 27 2010(Updated: )
arch/ia64/xen/faults.c in Xen 3.4 and 4.0 in Linux kernel 2.6.18, and possibly other kernel versions, when running on IA-64 architectures, allows local users to cause a denial of service and "turn on BE by modifying the user mask of the PSR," as demonstrated via exploitation of CVE-2006-0742.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
XenServer | =4.0.0 | |
XenServer | =3.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-2070 has a moderate severity rating due to its potential to cause a denial of service attack.
Fixing CVE-2010-2070 involves updating to a patched version of Xen, specifically versions beyond Xen 4.0.0 and 3.4.0.
Local users on IA-64 architectures running Xen 3.4.0 or 4.0.0 are affected by CVE-2010-2070.
CVE-2010-2070 is classified as a denial of service vulnerability.
CVE-2010-2070 cannot be exploited remotely as it requires local user access to the system.