PT-2018-2205 · Linux+2 · Linux Kernel+2
CVE-2018-10901
·
Publicado
2018-07-26
·
Atualizado
2023-02-24
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel's KVM virtualization subsystem (affected versions not specified)
Description
A flaw in the Linux kernel's KVM virtualization subsystem is related to inadequate access control. The issue is caused by the VMX code not restoring the GDT.LIMIT to the previous host value, instead setting it to 64KB. This allows a host's userspace code to place malicious entries in the GDT, particularly in the per-cpu variables, potentially enabling an attacker to escalate their privileges.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Initialization
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Centos
Linux Kernel
Red Hat