cbcvebase.
CVE-2018-15594
published 2018-08-20

CVE-2018-15594: arch/x86/kernel/paravirt.c in the Linux kernel before 4.18.1 mishandles certain indirect calls, which makes it easier for attackers to conduct Spectre-v2…

PriorityP422medium5.5CVSS 3.0
AVLACLPRLUINSUCHINAN
EPSS
0.55%
43.0th percentile
arch/x86/kernel/paravirt.c in the Linux kernel before 4.18.1 mishandles certain indirect calls, which makes it easier for attackers to conduct Spectre-v2 attacks against paravirtual guests.

Affected

15 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debianlinux< linux 4.17.15-1 (bookworm)linux 4.17.15-1 (bookworm)
linuxlinux_kernel< 4.18.14.18.1
linuxlinux_kernel>= 0 < 4.17.15-14.17.15-1
linuxlinux_kernel>= 0 < 4.17.15-14.17.15-1
linuxlinux_kernel>= 0 < 4.17.15-14.17.15-1
linuxlinux_kernel>= 0 < 4.17.15-14.17.15-1
linuxlinux_kernel>= 0 < 3.13.0-160.2103.13.0-160.210
linuxlinux_kernel>= 0 < 4.4.0-137.1634.4.0-137.163
linuxlinux_kernel>= 0 < 4.15.0-36.394.15.0-36.39

CVSS provenance

nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv7.8HIGH
vendor_ubuntu7.0HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.