关于 CVE-2010-0298 的漏洞信息

1. 漏洞描述
From NVD
The x86 emulator in KVM 83 does not use the Current Privilege Level (CPL) and I/O Privilege Level (IOPL) in determining the memory access available to CPL3 code, which allows guest OS users to cause a denial of service (guest OS crash) or gain privileges on the guest OS by leveraging access to a (1) IO port or (2) MMIO region, a related issue to CVE-2010-0306.
From 神龙GPT (AIGC)
KVM 83中的x86模拟器在确定SPL3代码可用的内存访问时,并未使用当前特权级别(CPL)和I/O特权级别(IOPL),这使得 guest OS 用户可以通过利用访问(1)IO端口或(2)MMIO区域来利用漏洞CVE-2010-0306,导致服务拒绝( guest OS 崩溃)或在 guest OS 中获取权限。这是一个与CVE-2010-0306相关的漏洞。
2. 漏洞评分(CVSS)
From NVD
NVD 暂无评分
From 神龙GPT (AIGC)
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
3. 漏洞类别
From NVD
NVD 暂无漏洞类别信息
From 神龙GPT (AIGC)
神龙GPT 暂无漏洞类别信息(请耐心等待)
Reference