First published: Mon Oct 04 2010(Updated: )
Invoking ioctl(KVM_RUN) while having invalid selector in fs and/or gs register (via LDT modifications) forces kernel to panic (DoS).
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/linux-2.6 | ||
Linux kernel | <2.6.36 | |
Fedora | =13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-3698 has a severity rating of Medium, as it can lead to a denial of service by causing the kernel to panic.
To fix CVE-2010-3698, update the Linux kernel to version 2.6.36 or later.
CVE-2010-3698 affects Linux kernels prior to version 2.6.36 and specific distributions such as Debian and Fedora 13.
CVE-2010-3698 facilitates a denial of service attack by causing a kernel panic when invoking ioctl(KVM_RUN) with invalid segment registers.
CVE-2010-3698 is generally not exploitable remotely as it requires local access to trigger the kernel panic.