Candidate: CVE-2009-3638 Description: integer overflow in kvm_dev_ioctl_get_supported_cpuid() References: http://www.openwall.com/lists/oss-security/2009/10/23/5 https://bugzilla.redhat.com/show_bug.cgi?id=530515 http://git.kernel.org/linus/6a54435560efdab1a08f429a954df4d6c740bddf Notes: introduced in 2.6.25 (commit 0771671749b59a507b6da4efb931c44d9691e248) Bugs: upstream: released (2.6.32-rc4) [6a54435560efdab1a08f429a954df4d6c740bddf], released (2.6.31.4) [779632b438a79ab1ed1f0da390712b12db3b2a58] linux-2.6: released (2.6.31-1) 2.6.18-etch-security: N/A "introduced in 2.6.25" 2.6.24-etch-security: N/A "introduced in 2.6.25" 2.6.26-lenny-security: released (2.6.26-19lenny2) [bugfix/x86/kvm-prevent-overflow-in-KVM_GET_SUPPORTED_CPUID.patch]