« List of all CVEs

CVE-2010-4255

Published: 1/25/2011 Last updated: 8/7/2024 Reserved: 11/16/2010

The fixup_page_fault function in arch/x86/traps.c in Xen 4.0.1 and earlier on 64-bit platforms, when paravirtualization is enabled, does not verify that kernel mode is used to call the handle_gdt_ldt_mapping_fault function, which allows guest OS users to cause a denial of service (host OS BUG_ON) via a crafted memory access.

CNA assigner: redhat (53f830b8-0a3f-465b-8143-3b8a9948e749) Requested by: n/a

Opam packages affected (2)

conf-xen xen-evtchn

Products affected (1)

Product Vendor Version
n/a n/a Windows 10 Version 1809 for x64-based Systems

References (18)