cbcvebase.
CVE-2018-1087
published 2018-05-15

CVE-2018-1087: kernel KVM before versions kernel 4.16, kernel 4.16-rc7, kernel 4.17-rc1, kernel 4.17-rc2 and kernel 4.17-rc3 is vulnerable to a flaw in the way the Linux…

high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
kernel KVM before versions kernel 4.16, kernel 4.16-rc7, kernel 4.17-rc1, kernel 4.17-rc2 and kernel 4.17-rc3 is vulnerable to a flaw in the way the Linux kernel's KVM hypervisor handled exceptions delivered after a stack switch operation via Mov SS or Pop SS instructions. During the stack switch operation, the processor did not deliver interrupts and exceptions, rather they are delivered once the first instruction after the stack switch is executed. An unprivileged KVM guest user could use this flaw to crash the guest or, potentially, escalate their privileges in the guest.

Affected

33 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debianlinux< linux 4.15.17-1 (bookworm)linux 4.15.17-1 (bookworm)
kernelkvm
kernelkvm
kernelkvm
kernelkvm
kernelkvm
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 4.15.17-14.15.17-1
linuxlinux_kernel>= 0 < 4.15.17-14.15.17-1
linuxlinux_kernel>= 0 < 4.15.17-14.15.17-1
linuxlinux_kernel>= 0 < 4.15.17-14.15.17-1
linuxlinux_kernel>= 0 < 3.13.0-147.1963.13.0-147.196
linuxlinux_kernel>= 0 < 4.4.0-124.1484.4.0-124.148
redhatenterprise_linux
redhatenterprise_linux_desktop
redhatenterprise_linux_server
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_aus

CVSS provenance

nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH