CVE-2013-1796
The kvm_set_msr_common function in arch/x86/kvm/x86.c in the Linux kernel through 3.8.4 does not ensure a required time_page alignment during an MSR_KVM_SYSTEM_TIME operation, which allows guest OS users to cause a denial of service (buffer overflow and host OS memory corruption) or possibly have unspecified other impact via a crafted application.
- Affected products
- Alt Linux, Centos, Debian, Linux Kernel, Red Hat, Suse, Kernel-Vanilla-Base, Kernel-Vanilla-Base-Debuginfo
- Linux Linux Kernel
- ≤ 3.8.4, 3.8.0, 3.8.1, 3.8.2, 3.8.3
- CVSS 2.0
- 6.8 MEDIUM
- EPSS
- 0.9% (59th percentile)
- Weakness
- CWE-119
- NVD status
- Modified
- Published
- 2013-03-22
CVE-2013-1796 at NVD
1 known exploit for CVE-2013-1796
Proof-of-concept code and exploit modules indexed by Sploitus