CVE-2018-10901
26.07.2018, 17:29
A flaw was found in Linux kernel's KVM virtualization subsystem. The VMX code does not restore the GDT.LIMIT to the previous host value, but instead sets it to 64KB. With a corrupted GDT limit a host's userspace code has an ability to place malicious entries in the GDT, particularly to the per-cpu variables. An attacker can use this to escalate their privileges.Enginsight
| Vendor | Product | Version |
|---|---|---|
| linux | linux_kernel | 𝑥 < 2.6.36 |
| redhat | enterprise_linux_desktop | 6.0 |
| redhat | enterprise_linux_server | 6.0 |
| redhat | enterprise_linux_server_aus | 6.4 |
| redhat | enterprise_linux_server_aus | 6.5 |
| redhat | enterprise_linux_server_aus | 6.6 |
| redhat | enterprise_linux_workstation | 6.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||
|---|---|---|---|---|---|---|---|
| linux |
| ||||||
| linux-aws |
| ||||||
| linux-azure |
| ||||||
| linux-azure-edge |
| ||||||
| linux-euclid |
| ||||||
| linux-flo |
| ||||||
| linux-gcp |
| ||||||
| linux-gke |
| ||||||
| linux-goldfish |
| ||||||
| linux-grouper |
| ||||||
| linux-hwe |
| ||||||
| linux-hwe-edge |
| ||||||
| linux-kvm |
| ||||||
| linux-lts-trusty |
| ||||||
| linux-lts-utopic |
| ||||||
| linux-lts-vivid |
| ||||||
| linux-lts-wily |
| ||||||
| linux-lts-xenial |
| ||||||
| linux-maguro |
| ||||||
| linux-mako |
| ||||||
| linux-manta |
| ||||||
| linux-oem |
| ||||||
| linux-raspi2 |
| ||||||
| linux-snapdragon |
|
Common Weakness Enumeration
References