The subpage MMIO initialization functionality in the subpage_register function in exec.c in QEMU-KVM, as used in the Hypervisor (aka rhev-hypervisor) in Red Hat Enterprise Virtualization (RHEV) 2.2 and KVM 83, does not properly select the index for access to the callback array, which allows guest OS users to cause a denial of service (guest OS crash) or possibly gain privileges via unspecified vectors.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
https://rhn.redhat.com/errata/RHSA-2010-0627.html | patch vendor advisory |
https://rhn.redhat.com/errata/RHSA-2010-0622.html | patch vendor advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=619411 | |
http://www.spinics.net/lists/kvm/msg39173.html | mailing list |