PublicDateAtUSN: 2010-11-26 Candidate: CVE-2010-3698 PublicDate: 2010-11-26 19:00:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3698 https://ubuntu.com/security/notices/USN-1072-1 https://ubuntu.com/security/notices/USN-1073-1 https://ubuntu.com/security/notices/USN-1074-1 https://ubuntu.com/security/notices/USN-1074-2 https://ubuntu.com/security/notices/USN-1081-1 https://ubuntu.com/security/notices/USN-1041-1 https://ubuntu.com/security/notices/USN-1093-1 https://ubuntu.com/security/notices/USN-1187-1 Description: The KVM implementation in the Linux kernel before 2.6.36 does not properly reload the FS and GS segment registers, which allows host OS users to cause a denial of service (host OS crash) via a KVM_RUN ioctl call in conjunction with a modified Local Descriptor Table (LDT). Ubuntu-Description: It was discovered that KVM did not correctly initialize certain CPU registers. A local attacker could exploit this to crash the system, leading to a denial of service. Notes: smb> There is no KVM in Dapper, so that cannot be affected. Maverick needed smb> some adaption as a previous stable patch moved code around. Lucid had smb> it already. Karmic mostly cherry-pick. Hardy needed more twisting. Bugs: https://bugzilla.redhat.com/show_bug.cgi?id=639879 Priority: medium Discovered-by: Assigned-to: smb CVSS: Patches_linux-source-2.6.15: upstream_linux-source-2.6.15: released (2.6.36) dapper_linux-source-2.6.15: not-affected hardy_linux-source-2.6.15: DNE karmic_linux-source-2.6.15: DNE lucid_linux-source-2.6.15: DNE maverick_linux-source-2.6.15: DNE natty_linux-source-2.6.15: DNE devel_linux-source-2.6.15: DNE Patches_linux: upstream: http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=9581d442b9058d3699b4be568b6e5eae38a41493 upstream_linux: released (2.6.36) dapper_linux: DNE hardy_linux: released (2.6.24-28.85) karmic_linux: released (2.6.31-22.73) lucid_linux: released (2.6.32-27.49) maverick_linux: released (2.6.35-26.45) natty_linux: not-affected (2.6.37-2.9) devel_linux: not-affected (2.6.39-0.0) upstream_linux-ec2: released (2.6.36) dapper_linux-ec2: DNE hardy_linux-ec2: DNE karmic_linux-ec2: released (2.6.31-307.27) lucid_linux-ec2: released (2.6.32-311.22) maverick_linux-ec2: ignored (binary supplied by "linux" now) natty_linux-ec2: DNE devel_linux-ec2: DNE Patches_linux-ti-omap4: upstream_linux-ti-omap4: released (2.6.36) dapper_linux-ti-omap4: DNE hardy_linux-ti-omap4: DNE karmic_linux-ti-omap4: DNE lucid_linux-ti-omap4: DNE maverick_linux-ti-omap4: not-affected natty_linux-ti-omap4: not-affected (2.6.38-1201.2) devel_linux-ti-omap4: not-affected (2.6.38-1309.13) upstream_linux-lts-backport-maverick: released (2.6.36) dapper_linux-lts-backport-maverick: DNE hardy_linux-lts-backport-maverick: DNE karmic_linux-lts-backport-maverick: DNE lucid_linux-lts-backport-maverick: released (2.6.35-28.50~lucid1) maverick_linux-lts-backport-maverick: DNE natty_linux-lts-backport-maverick: DNE devel_linux-lts-backport-maverick: DNE Patches_linux-mvl-dove: upstream_linux-mvl-dove: released (2.6.36) dapper_linux-mvl-dove: DNE hardy_linux-mvl-dove: DNE karmic_linux-mvl-dove: ignored (abandonded branch) lucid_linux-mvl-dove: released (2.6.32-213.29) maverick_linux-mvl-dove: released (2.6.32-414.30) natty_linux-mvl-dove: DNE devel_linux-mvl-dove: DNE Patches_linux-fsl-imx51: upstream_linux-fsl-imx51: released (2.6.36) dapper_linux-fsl-imx51: DNE hardy_linux-fsl-imx51: DNE karmic_linux-fsl-imx51: released (2.6.31-112.30) lucid_linux-fsl-imx51: released (2.6.31-608.22) maverick_linux-fsl-imx51: DNE natty_linux-fsl-imx51: DNE devel_linux-fsl-imx51: DNE Patches_linux-lts-backport-natty: upstream_linux-lts-backport-natty: released (2.6.36) hardy_linux-lts-backport-natty: DNE lucid_linux-lts-backport-natty: not-affected (2.6.38-1.27~lucid1) maverick_linux-lts-backport-natty: DNE natty_linux-lts-backport-natty: DNE devel_linux-lts-backport-natty: DNE