kernel KVM before versions kernel 4.16, kernel 4.16-rc7, kernel 4.17-rc1,...
Vulnerability Description
kernel KVM before versions kernel 4.16, kernel 4.16-rc7, kernel 4.17-rc1, kernel 4.17-rc2 and kernel 4.17-rc3 is vulnerable to a flaw in the way the Linux kernel's KVM hypervisor handled exceptions delivered after a stack switch operation via Mov SS or Pop SS instructions. During the stack switch operation, the processor did not deliver interrupts and exceptions, rather they are delivered once the first instruction after the stack switch is executed. An unprivileged KVM guest user could use this flaw to crash the guest or, potentially, escalate their privileges in the guest.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-1087
Credits & Attribution
No credits recorded in the NVD database.
References
- https://access.redhat.com/errata/RHSA-2018:1347
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1087
- http://www.securitytracker.com/id/1040862
- https://access.redhat.com/errata/RHSA-2018:1348
- https://www.debian.org/security/2018/dsa-4196
- https://access.redhat.com/errata/RHSA-2018:1355
- https://access.redhat.com/errata/RHSA-2018:1345
- https://access.redhat.com/security/vulnerabilities/pop_ss
- https://access.redhat.com/errata/RHSA-2018:1318
- https://access.redhat.com/errata/RHSA-2018:1524
- http://www.openwall.com/lists/oss-security/2018/05/08/5
- http://www.securityfocus.com/bid/104127
- https://usn.ubuntu.com/3641-2/
- https://usn.ubuntu.com/3641-1/
More from kernel
View All →Affected Vendor
kernel
View all reports →