The apicgettmcct function in arch/x86/kvm/lapic.c in the KVM subsystem in the Linux kernel through 3.12.5 allows guest OS users to cause a denial of service (divide-by-zero error and host OS crash) via crafted modifications of the TMICT value.
— Launchpad
Under guest controllable circumstances apicgettmcct will execute a divide by zero.
A privileged guest user could use this flaw to crash the host.
Acknowledgements:
Red Hat would like to thank Andrew Honig of Google for reporting this issue
Recommended actions to resolve this vulnerability, in priority order.
Upgrade
Upgrade debian/linux to a version that resolves this vulnerability.
Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.22-1Fixed in 6.12.25-1
Upgrade
Upgrade Linux kernel (KVM subsystem, arch/x86/kvm/lapic.c: apic_get_tmcct) to a version that resolves this vulnerability.
Fixed in 3.12.5
Compensating control
Mitigate the KVM guest-to-host DoS risk by isolating untrusted guests (e.g., run only trusted workloads on hosts with KVM) until the kernel issue is addressed.
SecAlerts Pty Ltd. 132 Wickham Terrace Fortitude Valley, QLD 4006, Australia info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.