Red Hat Bugzilla – Bug 1589890
CVE-2018-10853 kernel: kvm: guest userspace to guest kernel write
Last modified: 2018-10-04 07:03:28 EDT
A flaw was found in the way Linux kernel KVM hypervisor emulated instructions such as sgdt/sidt/fxsave/fxrstor. It did not check current privilege(CPL) level while emulating unprivileged instructions. An unprivileged guest user/process could use this flaw to potentially escalate privileges inside guest. Upstream patch: --------------- -> https://git.kernel.org/linus/3c9fa24ca7c9c47605672916491f79e8ccacb9e6 Issue introduced in: (kernel v4.10+) -------------------- -> https://git.kernel.org/linus/129a72a0d3c8e139a04512325384fe5ac119e74 Reference: ---------- -> http://www.openwall.com/lists/oss-security/2018/09/02/1
Created kernel tracking bugs for this issue: Affects: fedora-all [bug 1589892]
Acknowledgments: Name: Andy Lutomirski, Mika Penttilä