Package: kvm
Version: 85+dfsg-4.1
Severity: important
Tags: security

Hi,
the following CVE (Common Vulnerabilities & Exposures) id was
published for kvm.

CVE-2009-3722[0]:
| The handle_dr function in arch/x86/kvm/vmx.c in the KVM subsystem in
| the Linux kernel before 2.6.31.1 does not properly verify the Current
| Privilege Level (CPL) before accessing a debug register, which allows
| guest OS users to cause a denial of service (trap) on the host OS via
| a crafted application.

If you fix the vulnerability please also make sure to include the
CVE id in your changelog entry.

For further information see:

[0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3722
    http://security-tracker.debian.org/tracker/CVE-2009-3722



-- 
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Reply via email to