High severity7.8NVD Advisory· Published Nov 20, 2009· Updated Jun 16, 2026
CVE-2009-4004
CVE-2009-4004
Description
Buffer overflow in the kvm_vcpu_ioctl_x86_setup_mce function in arch/x86/kvm/x86.c in the KVM subsystem in the Linux kernel before 2.6.32-rc7 allows local users to cause a denial of service (memory corruption) or possibly gain privileges via a KVM_X86_SETUP_MCE IOCTL request that specifies a large number of Machine Check Exception (MCE) banks.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
9<2.6.32-rc7+ 8 more
- (no CPE)range: <2.6.32-rc7
- cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*range: <=2.6.31.14
- cpe:2.3:o:linux:linux_kernel:2.6.32:-:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.32:rc1:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.32:rc2:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.32:rc3:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.32:rc4:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.32:rc5:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.32:rc6:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
6- secunia.com/advisories/37357nvdBroken LinkVendor Advisory
- www.securityfocus.com/bid/37035nvdThird Party AdvisoryVDB Entry
- exchange.xforce.ibmcloud.com/vulnerabilities/54302nvdThird Party AdvisoryVDB Entry
- www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.32-rc7nvdBroken Link
- www.vupen.com/english/advisories/2009/3267nvdBroken Link
- git.kernel.orgnvd
News mentions
0No linked articles in our index yet.