CVE-2018-15594
published 2018-08-20CVE-2018-15594: arch/x86/kernel/paravirt.c in the Linux kernel before 4.18.1 mishandles certain indirect calls, which makes it easier for attackers to conduct Spectre-v2…
PriorityP422medium5.5CVSS 3.0
AVLACLPRLUINSUCHINAN
EPSS
0.55%
43.0th percentile
arch/x86/kernel/paravirt.c in the Linux kernel before 4.18.1 mishandles certain indirect calls, which makes it easier for attackers to conduct Spectre-v2 attacks against paravirtual guests.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | linux | < linux 4.17.15-1 (bookworm) | linux 4.17.15-1 (bookworm) |
| linux | linux_kernel | < 4.18.1 | 4.18.1 |
| linux | linux_kernel | >= 0 < 4.17.15-1 | 4.17.15-1 |
| linux | linux_kernel | >= 0 < 4.17.15-1 | 4.17.15-1 |
| linux | linux_kernel | >= 0 < 4.17.15-1 | 4.17.15-1 |
| linux | linux_kernel | >= 0 < 4.17.15-1 | 4.17.15-1 |
| linux | linux_kernel | >= 0 < 3.13.0-160.210 | 3.13.0-160.210 |
| linux | linux_kernel | >= 0 < 4.4.0-137.163 | 4.4.0-137.163 |
| linux | linux_kernel | >= 0 < 4.15.0-36.39 | 4.15.0-36.39 |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv7.8HIGH
vendor_ubuntu7.0HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9jqj-q3v6-cv9h: arch/x86/kernel/paravirt
ghsa_unreviewed·2022-05-13
CVE-2018-15594 [MEDIUM] CWE-200 GHSA-9jqj-q3v6-cv9h: arch/x86/kernel/paravirt
arch/x86/kernel/paravirt.c in the Linux kernel before 4.18.1 mishandles certain indirect calls, which makes it easier for attackers to conduct Spectre-v2 attacks against paravirtual guests.
OSV
linux-azure vulnerabilities
osv·2018-10-23·CVSS 5.6
CVE-2018-17182 [MEDIUM] linux-azure vulnerabilities
linux-azure vulnerabilities
USN-3777-1 fixed vulnerabilities in the Linux kernel for Ubuntu 18.04
%LTS. This update provides the corresponding updates for the
Linux kernel for Azure Cloud systems.
Jann Horn discovered that the vmacache subsystem did not properly handle
sequence number overflows, leading to a use-after-free vulnerability. A
local attacker could use this to cause a denial of service (system crash)
or execute arbitrary code. (CVE-2018-17182)
It was discovered that the paravirtualization implementation in the Linux
kernel did not properly handle some indirect calls, reducing the
effectiveness of Spectre v2 mitigations for paravirtual guests. A local
attacker could use this to expose sensitive information. (CVE-2018-15594)
It was discovered that microprocessors utilizing sp
OSV
linux vulnerabilities
osv·2018-10-01·CVSS 7.0
CVE-2018-15594 [HIGH] linux vulnerabilities
linux vulnerabilities
It was discovered that the paravirtualization implementation in the Linux
kernel did not properly handle some indirect calls, reducing the
effectiveness of Spectre v2 mitigations for paravirtual guests. A local
attacker could use this to expose sensitive information. (CVE-2018-15594)
It was discovered that microprocessors utilizing speculative execution and
prediction of return addresses via Return Stack Buffer (RSB) may allow
unauthorized memory reads via sidechannel attacks. An attacker could use
this to expose sensitive information. (CVE-2018-15572)
It was discovered that an integer overflow vulnerability existed in the
Linux kernel when loading an executable to run. A local attacker could use
this to gain administrative privileges. (CVE-2018-14634)
It was disc
OSV
linux-hwe, linux-gcp vulnerabilities
osv·2018-10-01·CVSS 7.8
[HIGH] linux-hwe, linux-gcp vulnerabilities
linux-hwe, linux-gcp vulnerabilities
USN-3777-1 fixed vulnerabilities in the Linux kernel for Ubuntu 18.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 18.04 LTS for Ubuntu
16.04 LTS.
Jann Horn discovered that the vmacache subsystem did not properly handle
sequence number overflows, leading to a use-after-free vulnerability. A
local attacker could use this to cause a denial of service (system crash)
or execute arbitrary code. (CVE-2018-17182)
It was discovered that the paravirtualization implementation in the Linux
kernel did not properly handle some indirect calls, reducing the
effectiveness of Spectre v2 mitigations for paravirtual guests. A local
attacker could use this to expose sensitive information. (CVE-2018-15594)
OSV
linux, linux-aws, linux-gcp, linux-kvm, linux-oem, linux-raspi2 vulnerabilities
osv·2018-10-01·CVSS 7.8
CVE-2018-17182 [HIGH] linux, linux-aws, linux-gcp, linux-kvm, linux-oem, linux-raspi2 vulnerabilities
linux, linux-aws, linux-gcp, linux-kvm, linux-oem, linux-raspi2 vulnerabilities
Jann Horn discovered that the vmacache subsystem did not properly handle
sequence number overflows, leading to a use-after-free vulnerability. A
local attacker could use this to cause a denial of service (system crash)
or execute arbitrary code. (CVE-2018-17182)
It was discovered that the paravirtualization implementation in the Linux
kernel did not properly handle some indirect calls, reducing the
effectiveness of Spectre v2 mitigations for paravirtual guests. A local
attacker could use this to expose sensitive information. (CVE-2018-15594)
It was discovered that microprocessors utilizing speculative execution and
prediction of return addresses via Return Stack Buffer (RSB) may allow
unauthorized memory rea
OSV
linux-lts-xenial, linux-aws vulnerabilities
osv·2018-10-01·CVSS 5.5
[MEDIUM] linux-lts-xenial, linux-aws vulnerabilities
linux-lts-xenial, linux-aws vulnerabilities
USN-3776-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 LTS.
Jann Horn discovered that the vmacache subsystem did not properly handle
sequence number overflows, leading to a use-after-free vulnerability. A
local attacker could use this to cause a denial of service (system crash)
or execute arbitrary code. (CVE-2018-17182)
It was discovered that the paravirtualization implementation in the Linux
kernel did not properly handle some indirect calls, reducing the
effectiveness of Spectre v2 mitigations for paravirtual guests. A local
attacker could use this to expose sensitive information. (CVE-2018
OSV
linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
osv·2018-10-01·CVSS 5.5
CVE-2018-17182 [MEDIUM] linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
Jann Horn discovered that the vmacache subsystem did not properly handle
sequence number overflows, leading to a use-after-free vulnerability. A
local attacker could use this to cause a denial of service (system crash)
or execute arbitrary code. (CVE-2018-17182)
It was discovered that the paravirtualization implementation in the Linux
kernel did not properly handle some indirect calls, reducing the
effectiveness of Spectre v2 mitigations for paravirtual guests. A local
attacker could use this to expose sensitive information. (CVE-2018-15594)
It was discovered that microprocessors utilizing speculative execution and
prediction of return addresses via Return Stack Buffer (RSB) may allow
unauthorized memory reads v
OSV
CVE-2018-15594: arch/x86/kernel/paravirt
osv·2018-08-20·CVSS 5.5
CVE-2018-15594 [MEDIUM] CVE-2018-15594: arch/x86/kernel/paravirt
arch/x86/kernel/paravirt.c in the Linux kernel before 4.18.1 mishandles certain indirect calls, which makes it easier for attackers to conduct Spectre-v2 attacks against paravirtual guests.
Ubuntu
Linux kernel (Azure) vulnerabilities
vendor_ubuntu·2018-10-23·CVSS 5.6
CVE-2017-5715 [MEDIUM] Linux kernel (Azure) vulnerabilities
Title: Linux kernel (Azure) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3777-1 fixed vulnerabilities in the Linux kernel for Ubuntu 18.04
%LTS. This update provides the corresponding updates for the
Linux kernel for Azure Cloud systems.
Jann Horn discovered that the vmacache subsystem did not properly handle
sequence number overflows, leading to a use-after-free vulnerability. A
local attacker could use this to cause a denial of service (system crash)
or execute arbitrary code. (CVE-2018-17182)
It was discovered that the paravirtualization implementation in the Linux
kernel did not properly handle some indirect calls, reducing the
effectiveness of Spectre v2 mitigations for paravirtual guests. A local
attacker could use this to expose sensitive
Ubuntu
Linux kernel (HWE) vulnerabilities
vendor_ubuntu·2018-10-01·CVSS 7.0
CVE-2018-10853 [HIGH] Linux kernel (HWE) vulnerabilities
Title: Linux kernel (HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3777-1 fixed vulnerabilities in the Linux kernel for Ubuntu 18.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 18.04 LTS for Ubuntu
16.04 LTS.
Jann Horn discovered that the vmacache subsystem did not properly handle
sequence number overflows, leading to a use-after-free vulnerability. A
local attacker could use this to cause a denial of service (system crash)
or execute arbitrary code. (CVE-2018-17182)
It was discovered that the paravirtualization implementation in the Linux
kernel did not properly handle some indirect calls, reducing the
effectiveness of Spectre v2 mitigations for paravirtual guests. A local
at
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2018-10-01·CVSS 7.0
CVE-2018-14633 [HIGH] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3775-1 fixed vulnerabilities in the Linux kernel for Ubuntu 14.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 14.04 LTS for Ubuntu
12.04 ESM.
It was discovered that the paravirtualization implementation in the Linux
kernel did not properly handle some indirect calls, reducing the
effectiveness of Spectre v2 mitigations for paravirtual guests. A local
attacker could use this to expose sensitive information. (CVE-2018-15594)
It was discovered that microprocessors utilizing speculative execution and
prediction of return addresses via Return Stack Buffer (RSB) may allow
unauthorized memory reads via sidechan
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2018-10-01·CVSS 5.5
CVE-2017-18216 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Jann Horn discovered that the vmacache subsystem did not properly handle
sequence number overflows, leading to a use-after-free vulnerability. A
local attacker could use this to cause a denial of service (system crash)
or execute arbitrary code. (CVE-2018-17182)
It was discovered that the paravirtualization implementation in the Linux
kernel did not properly handle some indirect calls, reducing the
effectiveness of Spectre v2 mitigations for paravirtual guests. A local
attacker could use this to expose sensitive information. (CVE-2018-15594)
It was discovered that microprocessors utilizing speculative execution and
prediction of return addresses via Return Stack Buffer (RSB) may allow
u
Ubuntu
Linux kernel (Xenial HWE) vulnerabilities
vendor_ubuntu·2018-10-01·CVSS 5.5
CVE-2017-18216 [MEDIUM] Linux kernel (Xenial HWE) vulnerabilities
Title: Linux kernel (Xenial HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3776-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 LTS.
Jann Horn discovered that the vmacache subsystem did not properly handle
sequence number overflows, leading to a use-after-free vulnerability. A
local attacker could use this to cause a denial of service (system crash)
or execute arbitrary code. (CVE-2018-17182)
It was discovered that the paravirtualization implementation in the Linux
kernel did not properly handle some indirect calls, reducing the
effectiveness of Spectre v2 mitigations for paravirtual guests. A l
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2018-10-01·CVSS 7.0
CVE-2018-10853 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Jann Horn discovered that the vmacache subsystem did not properly handle
sequence number overflows, leading to a use-after-free vulnerability. A
local attacker could use this to cause a denial of service (system crash)
or execute arbitrary code. (CVE-2018-17182)
It was discovered that the paravirtualization implementation in the Linux
kernel did not properly handle some indirect calls, reducing the
effectiveness of Spectre v2 mitigations for paravirtual guests. A local
attacker could use this to expose sensitive information. (CVE-2018-15594)
It was discovered that microprocessors utilizing speculative execution and
prediction of return addresses via Return Stack Buffer (RSB) may allow
u
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2018-10-01·CVSS 7.0
CVE-2018-14633 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that the paravirtualization implementation in the Linux
kernel did not properly handle some indirect calls, reducing the
effectiveness of Spectre v2 mitigations for paravirtual guests. A local
attacker could use this to expose sensitive information. (CVE-2018-15594)
It was discovered that microprocessors utilizing speculative execution and
prediction of return addresses via Return Stack Buffer (RSB) may allow
unauthorized memory reads via sidechannel attacks. An attacker could use
this to expose sensitive information. (CVE-2018-15572)
It was discovered that an integer overflow vulnerability existed in the
Linux kernel when loading an executable to run. A local attacker
Red Hat
kernel: Mishandling of indirect calls weakens Spectre mitigation for paravirtual guests
vendor_redhat·2018-08-03·CVSS 5.5
CVE-2018-15594 [MEDIUM] CWE-200 kernel: Mishandling of indirect calls weakens Spectre mitigation for paravirtual guests
kernel: Mishandling of indirect calls weakens Spectre mitigation for paravirtual guests
arch/x86/kernel/paravirt.c in the Linux kernel before 4.18.1 mishandles certain indirect calls, which makes it easier for attackers to conduct Spectre-v2 attacks against paravirtual guests.
It was found that paravirt_patch_call/jump() functions in the arch/x86/kernel/paravirt.c in the Linux kernel mishandles certain indirect calls, which makes it easier for attackers to conduct Spectre-v2 attacks against paravirtualized guests.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Will not fix
Package: kernel-alt (Red Hat Enterprise Linux 7) - Will not fix
Package: kernel (Red Hat Enterprise Linux 8) - Will not fix
Package: realtime-kernel (Red
Debian
CVE-2018-15594: linux - arch/x86/kernel/paravirt.c in the Linux kernel before 4.18.1 mishandles certain ...
vendor_debian·2018·CVSS 5.5
CVE-2018-15594 [MEDIUM] CVE-2018-15594: linux - arch/x86/kernel/paravirt.c in the Linux kernel before 4.18.1 mishandles certain ...
arch/x86/kernel/paravirt.c in the Linux kernel before 4.18.1 mishandles certain indirect calls, which makes it easier for attackers to conduct Spectre-v2 attacks against paravirtual guests.
Scope: local
bookworm: resolved (fixed in 4.17.15-1)
bullseye: resolved (fixed in 4.17.15-1)
forky: resolved (fixed in 4.17.15-1)
sid: resolved (fixed in 4.17.15-1)
trixie: resolved (fixed in 4.17.15-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-15594 kernel: Mishandling of indirect calls weakens Spectre mitigation for paravirtual guests
bugzilla·2018-08-23·CVSS 5.5
CVE-2018-15594 [MEDIUM] CVE-2018-15594 kernel: Mishandling of indirect calls weakens Spectre mitigation for paravirtual guests
CVE-2018-15594 kernel: Mishandling of indirect calls weakens Spectre mitigation for paravirtual guests
It was found that arch/x86/kernel/paravirt.c in the Linux kernel before 4.18.1 It was found that paravirt_patch_call/jump() functions in the arch/x86/kernel/paravirt.c in the Linux kernel mishandle certain indirect calls, which makes it easier for attackers to conduct Spectre-v2 attacks against paravirtualized guests.
An upstream patch:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=5800dc5c19f34e6e03b5adab1282535cb102fafd
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 1620557]
---
This was fixed for Fedora users with the 4.17.14-202 kernel update.
---
This issue has been addressed in the following products:
Red
Bugzilla
CVE-2018-15594 kernel: Mishandling of indirect calls weakens Spectre mitigations for paravirtual guests [fedora-all]
bugzilla·2018-08-23·CVSS 5.5
CVE-2018-15594 [MEDIUM] CVE-2018-15594 kernel: Mishandling of indirect calls weakens Spectre mitigations for paravirtual guests [fedora-all]
CVE-2018-15594 kernel: Mishandling of indirect calls weakens Spectre mitigations for paravirtual guests [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this is
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=5800dc5c19f34e6e03b5adab1282535cb102fafdhttp://lists.opensuse.org/opensuse-security-announce/2019-05/msg00043.htmlhttp://www.securityfocus.com/bid/105120http://www.securitytracker.com/id/1041601https://access.redhat.com/errata/RHSA-2019:2029https://access.redhat.com/errata/RHSA-2019:2043https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.18.1https://github.com/torvalds/linux/commit/5800dc5c19f34e6e03b5adab1282535cb102fafdhttps://lists.debian.org/debian-lts-announce/2018/10/msg00003.htmlhttps://twitter.com/grsecurity/status/1029324426142199808https://usn.ubuntu.com/3775-1/https://usn.ubuntu.com/3775-2/https://usn.ubuntu.com/3776-1/https://usn.ubuntu.com/3776-2/https://usn.ubuntu.com/3777-1/https://usn.ubuntu.com/3777-2/https://usn.ubuntu.com/3777-3/https://www.debian.org/security/2018/dsa-4308http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=5800dc5c19f34e6e03b5adab1282535cb102fafdhttp://lists.opensuse.org/opensuse-security-announce/2019-05/msg00043.htmlhttp://www.securityfocus.com/bid/105120http://www.securitytracker.com/id/1041601https://access.redhat.com/errata/RHSA-2019:2029https://access.redhat.com/errata/RHSA-2019:2043https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.18.1https://github.com/torvalds/linux/commit/5800dc5c19f34e6e03b5adab1282535cb102fafdhttps://lists.debian.org/debian-lts-announce/2018/10/msg00003.htmlhttps://twitter.com/grsecurity/status/1029324426142199808https://usn.ubuntu.com/3775-1/https://usn.ubuntu.com/3775-2/https://usn.ubuntu.com/3776-1/https://usn.ubuntu.com/3776-2/https://usn.ubuntu.com/3777-1/https://usn.ubuntu.com/3777-2/https://usn.ubuntu.com/3777-3/https://www.debian.org/security/2018/dsa-4308
2018-08-20
Published