CVE-2018-1087
published 2018-05-15CVE-2018-1087: kernel KVM before versions kernel 4.16, kernel 4.16-rc7, kernel 4.17-rc1, kernel 4.17-rc2 and kernel 4.17-rc3 is vulnerable to a flaw in the way the Linux…
PriorityP340high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EPSS
0.77%
51.6th percentile
kernel KVM before versions kernel 4.16, kernel 4.16-rc7, kernel 4.17-rc1, kernel 4.17-rc2 and kernel 4.17-rc3 is vulnerable to a flaw in the way the Linux kernel's KVM hypervisor handled exceptions delivered after a stack switch operation via Mov SS or Pop SS instructions. During the stack switch operation, the processor did not deliver interrupts and exceptions, rather they are delivered once the first instruction after the stack switch is executed. An unprivileged KVM guest user could use this flaw to crash the guest or, potentially, escalate their privileges in the guest.
Affected
33 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | linux | < linux 4.15.17-1 (bookworm) | linux 4.15.17-1 (bookworm) |
| kernel | kvm | — | — |
| kernel | kvm | — | — |
| kernel | kvm | — | — |
| kernel | kvm | — | — |
| kernel | kvm | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 4.15.17-1 | 4.15.17-1 |
| linux | linux_kernel | >= 0 < 4.15.17-1 | 4.15.17-1 |
| linux | linux_kernel | >= 0 < 4.15.17-1 | 4.15.17-1 |
| linux | linux_kernel | >= 0 < 4.15.17-1 | 4.15.17-1 |
| linux | linux_kernel | >= 0 < 3.13.0-147.196 | 3.13.0-147.196 |
| linux | linux_kernel | >= 0 < 4.4.0-124.148 | 4.4.0-124.148 |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian8.0HIGH
vendor_redhat8.0HIGH
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2018-05-08·CVSS 5.5
CVE-2018-1000199 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3641-1 fixed vulnerabilities in the Linux kernel for Ubuntu 14.04
LTS, Ubuntu 16.04 LTS, and Ubuntu 17.10. This update provides the
corresponding updates for Ubuntu 12.04 ESM.
Nick Peterson discovered that the Linux kernel did not properly handle
debug exceptions following a MOV/POP to SS instruction. A local attacker
could use this to cause a denial of service (system crash). This issue only
affected the amd64 architecture. (CVE-2018-8897)
Andy Lutomirski discovered that the KVM subsystem of the Linux kernel did
not properly emulate the ICEBP instruction following a MOV/POP to SS
instruction. A local attacker in a KVM virtual machine could use this to
cause a denial of service (gue
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2018-05-08·CVSS 5.5
CVE-2018-1000199 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Nick Peterson discovered that the Linux kernel did not
properly handle debug exceptions following a MOV/POP to SS
instruction. A local attacker could use this to cause a denial
of service (system crash). This issue only affected the amd64
architecture. (CVE-2018-8897)
Andy Lutomirski discovered that the KVM subsystem of the Linux kernel
did not properly emulate the ICEBP instruction following a MOV/POP
to SS instruction. A local attacker in a KVM virtual machine could
use this to cause a denial of service (guest VM crash) or possibly
escalate privileges inside of the virtual machine. This issue only
affected the i386 and amd64 architectures. (CVE-2018-1087)
Andy Lutomirski discovered th
Red Hat
Kernel: KVM: error in exception handling leads to wrong debug stack value
vendor_redhat·2018-05-08·CVSS 8.0
CVE-2018-1087 [HIGH] CWE-250 Kernel: KVM: error in exception handling leads to wrong debug stack value
Kernel: KVM: error in exception handling leads to wrong debug stack value
kernel KVM before versions kernel 4.16, kernel 4.16-rc7, kernel 4.17-rc1, kernel 4.17-rc2 and kernel 4.17-rc3 is vulnerable to a flaw in the way the Linux kernel's KVM hypervisor handled exceptions delivered after a stack switch operation via Mov SS or Pop SS instructions. During the stack switch operation, the processor did not deliver interrupts and exceptions, rather they are delivered once the first instruction after the stack switch is executed. An unprivileged KVM guest user could use this flaw to crash the guest or, potentially, escalate their privileges in the guest.
A flaw was found in the way the Linux kernel's KVM hypervisor handled exceptions delivered after a stack switch operation via Mov SS or Pop SS
Debian
CVE-2018-1087: linux - kernel KVM before versions kernel 4.16, kernel 4.16-rc7, kernel 4.17-rc1, kernel...
vendor_debian·2018·CVSS 8.0
CVE-2018-1087 [HIGH] CVE-2018-1087: linux - kernel KVM before versions kernel 4.16, kernel 4.16-rc7, kernel 4.17-rc1, kernel...
kernel KVM before versions kernel 4.16, kernel 4.16-rc7, kernel 4.17-rc1, kernel 4.17-rc2 and kernel 4.17-rc3 is vulnerable to a flaw in the way the Linux kernel's KVM hypervisor handled exceptions delivered after a stack switch operation via Mov SS or Pop SS instructions. During the stack switch operation, the processor did not deliver interrupts and exceptions, rather they are delivered once the first instruction after the stack switch is executed. An unprivileged KVM guest user could use this flaw to crash the guest or, potentially, escalate their privileges in the guest.
Scope: local
bookworm: resolved (fixed in 4.15.17-1)
bullseye: resolved (fixed in 4.15.17-1)
forky: resolved (fixed in 4.15.17-1)
sid: resolved (fixed in 4.15.17-1)
trixie: resolved (fixed in 4.15.17-1)
GHSA
GHSA-j658-wqr4-q3w7: kernel KVM before versions kernel 4
ghsa_unreviewed·2022-05-13
CVE-2018-1087 [HIGH] GHSA-j658-wqr4-q3w7: kernel KVM before versions kernel 4
kernel KVM before versions kernel 4.16, kernel 4.16-rc7, kernel 4.17-rc1, kernel 4.17-rc2 and kernel 4.17-rc3 is vulnerable to a flaw in the way the Linux kernel's KVM hypervisor handled exceptions delivered after a stack switch operation via Mov SS or Pop SS instructions. During the stack switch operation, the processor did not deliver interrupts and exceptions, rather they are delivered once the first instruction after the stack switch is executed. An unprivileged KVM guest user could use this flaw to crash the guest or, potentially, escalate their privileges in the guest.
OSV
CVE-2018-1087: kernel KVM before versions kernel 4
osv·2018-05-15·CVSS 7.8
CVE-2018-1087 [HIGH] CVE-2018-1087: kernel KVM before versions kernel 4
kernel KVM before versions kernel 4.16, kernel 4.16-rc7, kernel 4.17-rc1, kernel 4.17-rc2 and kernel 4.17-rc3 is vulnerable to a flaw in the way the Linux kernel's KVM hypervisor handled exceptions delivered after a stack switch operation via Mov SS or Pop SS instructions. During the stack switch operation, the processor did not deliver interrupts and exceptions, rather they are delivered once the first instruction after the stack switch is executed. An unprivileged KVM guest user could use this flaw to crash the guest or, potentially, escalate their privileges in the guest.
OSV
linux, linux-aws, linux-azure, linux-euclid, linux-gcp, linux-hwe, linux-kvm, linux-lts-xenial, linux-oem, linux-raspi2, linux-snapdragon vulnerabilities
osv·2018-05-08·CVSS 5.5
CVE-2018-8897 [MEDIUM] linux, linux-aws, linux-azure, linux-euclid, linux-gcp, linux-hwe, linux-kvm, linux-lts-xenial, linux-oem, linux-raspi2, linux-snapdragon vulnerabilities
linux, linux-aws, linux-azure, linux-euclid, linux-gcp, linux-hwe, linux-kvm, linux-lts-xenial, linux-oem, linux-raspi2, linux-snapdragon vulnerabilities
Nick Peterson discovered that the Linux kernel did not
properly handle debug exceptions following a MOV/POP to SS
instruction. A local attacker could use this to cause a denial
of service (system crash). This issue only affected the amd64
architecture. (CVE-2018-8897)
Andy Lutomirski discovered that the KVM subsystem of the Linux kernel
did not properly emulate the ICEBP instruction following a MOV/POP
to SS instruction. A local attacker in a KVM virtual machine could
use this to cause a denial of service (guest VM crash) or possibly
escalate privileges inside of the virtual machine. This issue only
affected the i386 and amd64 architect
No detection rules found.
No public exploits indexed.
http://www.openwall.com/lists/oss-security/2018/05/08/5http://www.securityfocus.com/bid/104127http://www.securitytracker.com/id/1040862https://access.redhat.com/errata/RHSA-2018:1318https://access.redhat.com/errata/RHSA-2018:1345https://access.redhat.com/errata/RHSA-2018:1347https://access.redhat.com/errata/RHSA-2018:1348https://access.redhat.com/errata/RHSA-2018:1355https://access.redhat.com/errata/RHSA-2018:1524https://access.redhat.com/security/vulnerabilities/pop_sshttps://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1087https://usn.ubuntu.com/3641-1/https://usn.ubuntu.com/3641-2/https://www.debian.org/security/2018/dsa-4196http://www.openwall.com/lists/oss-security/2018/05/08/5http://www.securityfocus.com/bid/104127http://www.securitytracker.com/id/1040862https://access.redhat.com/errata/RHSA-2018:1318https://access.redhat.com/errata/RHSA-2018:1345https://access.redhat.com/errata/RHSA-2018:1347https://access.redhat.com/errata/RHSA-2018:1348https://access.redhat.com/errata/RHSA-2018:1355https://access.redhat.com/errata/RHSA-2018:1524https://access.redhat.com/security/vulnerabilities/pop_sshttps://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1087https://usn.ubuntu.com/3641-1/https://usn.ubuntu.com/3641-2/https://www.debian.org/security/2018/dsa-4196
2018-05-15
Published