Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The msr_mtrr_valid function in arch/x86/kvm/mtrr.c in the Linux kernel before 4.6.1 supports MSR 0x2f8, which allows guest OS users to read or write to the kvm_arch_vcpu data structure, and consequently obtain sensitive information or cause a denial of service (system crash), via a crafted ioctl call.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Linux kernel 安全漏洞
Vulnerability Description
Linux kernel是美国Linux基金会发布的开源操作系统Linux所使用的内核。NFSv4 implementation是其中的一个分布式文件系统协议。 Linux kernel 4.6及之前版本的arch/x86/kvm/mtrr.c文件中的‘msr_mtrr_valid’函数存在安全漏洞,该漏洞源于程序支持MSR 0x2f8。虚拟机端攻击者可借助ioctl调用利用该漏洞读取或写入kvm_arch_vcpu数据结构体,获取敏感信息或造成拒绝服务(系统崩溃)。
CVSS Information
N/A
Vulnerability Type
N/A