Linux kernel built with the Kernel-based Virtual Machine(CONFIG_KVM) support is vulnerable an incorrect segment selector(SS) value error. It could occur loading values into SS register in long mode. A user/process inside guest could use this flaw to crash the guest resulting in DoS or potentially escalate their privileges inside guest. Upstream patch: --------------- -> https://git.kernel.org/linus/33ab91103b3415e12457e3104f0e4517ce12d0f3 Note: On Intel CPUs it'd corrupt the guest state resulting in DoS; Whereas on AMD CPUs it could potentially escalate privileges inside guest. Reference: ---------- -> http://www.openwall.com/lists/oss-security/2017/01/19/2
Acknowledgments: Name: Xiaohan Zhang (Huawei Inc.)
Created kernel tracking bugs for this issue: Affects: fedora-all [bug 1414736]
Statement: This issue does not affect the versions of the kernel package as shipped with Red Hat Enterprise Linux 5, 6 and Red Hat Enterprise MRG 2. This issue affects the versions of the Linux kernel as shipped with Red Hat Enterprise Linux 7. Future kernel updates for Red Hat Enterprise Linux 7 may address this issue.
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2017:1615 https://access.redhat.com/errata/RHSA-2017:1615
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2017:1616 https://access.redhat.com/errata/RHSA-2017:1616