Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2018-8897

CWE-362Race ConditionCWE-25018 documents12 sources
Severity
7.8HIGH
EPSS
24.7%
top 3.85%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedMay 8
Latest updateMay 13

Description

A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Developer's Manual (SDM) was mishandled in the development of some or all operating-system kernels, resulting in unexpected behavior for #DB exceptions that are deferred by MOV SS or POP SS, as demonstrated by (for example) privilege escalation in Windows, macOS, some Xen configurations, or FreeBSD, or a Linux kernel crash. The MOV to SS and POP SS instructions inhibit interrupts (including NMIs), data b

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages28 packages

NVDapple/mac_os_x< 10.13.4
NVDfreebsd/freebsd11.011.1
Debianlinux< 4.15.17-1+3
Ubuntulinux< 3.13.0-147.196+1
Ubuntulinux-aws< 4.4.0-1019.19+1

Also affects: Debian Linux 7.0, 8.0, 9.0, Ubuntu Linux 14.04, 16.04, 17.10

Patches

🔴Vulnerability Details

4
GHSA
GHSA-j2cv-h77g-5p95: A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Developer's Manual (SDM) was mishandled in the developmen2022-05-13
OSV
CVE-2018-8897: A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Developer's Manual (SDM) was mishandled in the developmen2018-05-08
OSV
linux, linux-aws, linux-azure, linux-euclid, linux-gcp, linux-hwe, linux-kvm, linux-lts-xenial, linux-oem, linux-raspi2, linux-snapdragon vulnerabilities2018-05-08
CVEList
CVE-2018-8897: A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Developer's Manual (SDM) was mishandled in the developmen2018-05-08

💥Exploits & PoCs

2
Exploit-DB
Microsoft Windows - POP/MOV SS Local Privilege Elevation (Metasploit)2018-07-13
Exploit-DB
Microsoft Windows - 'POP/MOV SS' Privilege Escalation2018-05-22

📋Vendor Advisories

9
Red Hat
kernel: error in exception handling leads to DoS (CVE-2018-8897 regression)2018-07-10
Apple
CVE-2018-8897: macOS High Sierra 10.13.5, Security Update 2018-003 Sierra, Security Update 2018-003 El Capitan2018-06-01
Microsoft
Windows Kernel Elevation of Privilege Vulnerability2018-05-08
Ubuntu
Linux kernel vulnerabilities2018-05-08
Ubuntu
Linux kernel vulnerabilities2018-05-08

💬Community

2
Bugzilla
CVE-2018-10872 kernel: error in exception handling leads to DoS (CVE-2018-8897 regression)2018-06-28
Bugzilla
CVE-2018-8897 Kernel: error in exception handling leads to DoS2018-04-13
CVE-2018-8897 (HIGH CVSS 7.8) | A statement in the System Programmi | cvebase.io