cbcvebase.
CVE-2018-18021
published 2018-10-07

CVE-2018-18021: arch/arm64/kvm/guest.c in KVM in the Linux kernel before 4.18.12 on the arm64 platform mishandles the KVM_SET_ON_REG ioctl. This is exploitable by attackers…

PriorityP429high7.1CVSS 3.0
AVLACLPRLUINSUCNIHAH
EPSS
0.57%
44.0th percentile
arch/arm64/kvm/guest.c in KVM in the Linux kernel before 4.18.12 on the arm64 platform mishandles the KVM_SET_ON_REG ioctl. This is exploitable by attackers who can create virtual machines. An attacker can arbitrarily redirect the hypervisor flow of control (with full register control). An attacker can also cause a denial of service (hypervisor panic) via an illegal exception return. This occurs because of insufficient restrictions on userspace access to the core register file, and because PSTATE.M validation does not prevent unintended execution modes.

Affected

11 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debianlinux< linux 4.18.10-2 (bookworm)linux 4.18.10-2 (bookworm)
linuxlinux_kernel< 4.18.124.18.12
linuxlinux_kernel>= 0 < 4.18.10-24.18.10-2
linuxlinux_kernel>= 0 < 4.18.10-24.18.10-2
linuxlinux_kernel>= 0 < 4.18.10-24.18.10-2
linuxlinux_kernel>= 0 < 4.18.10-24.18.10-2
linuxlinux_kernel>= 0 < 4.4.0-139.1654.4.0-139.165
linuxlinux_kernel>= 0 < 4.15.0-47.504.15.0-47.50

CVSS provenance

nvdv3.07.1HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
nvdv2.03.6LOWAV:L/AC:L/Au:N/C:N/I:P/A:P
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.