cbcvebase.
CVE-2018-16882
published 2019-01-03

CVE-2018-16882: A use-after-free issue was found in the way the Linux kernel's KVM hypervisor processed posted interrupts when nested(=1) virtualization is enabled. In…

PriorityP343high8.8CVSS 3.1
AVLACLPRLUINSCCHIHAH
EPSS
0.36%
28.7th percentile
A use-after-free issue was found in the way the Linux kernel's KVM hypervisor processed posted interrupts when nested(=1) virtualization is enabled. In nested_get_vmcs12_pages(), in case of an error while processing posted interrupt address, it unmaps the 'pi_desc_page' without resetting 'pi_desc' descriptor address, which is later used in pi_test_and_clear_on(). A guest user/process could use this flaw to crash the host kernel resulting in DoS or potentially gain privileged access to a system. Kernel versions before 4.14.91 and before 4.19.13 are vulnerable.

Affected

15 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debianlinux< linux 4.19.13-1 (bookworm)linux 4.19.13-1 (bookworm)
linuxlinux_kernel>= 0 < 4.19.13-14.19.13-1
linuxlinux_kernel>= 0 < 4.19.13-14.19.13-1
linuxlinux_kernel>= 0 < 4.19.13-14.19.13-1
linuxlinux_kernel>= 0 < 4.19.13-14.19.13-1
linuxlinux_kernel>= 0 < 4.15.0-44.474.15.0-44.47
linuxlinux_kernel>= 0 < 4.15.0-45.484.15.0-45.48
linuxlinux_kernel>= 4.14 < 4.14.914.14.91
linuxlinux_kernel>= 4.15 < 4.19.134.19.13
the_linux_foundationkernel
the_linux_foundationkernel

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
nvdv3.06.1MEDIUMCVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:L/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
vendor_ubuntu5.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.