Red Hat Bugzilla – Bug 1635475
CVE-2018-18021 kernel: Privilege escalation on arm64 via KVM hypervisor
Last modified: 2018-10-24 11:48:54 EDT
The Linux kernel has vulnerability on 64-bit ARM architectures that allows an attacker to escalate privileges. A local attacker with permission to create KVM-based virtual machines can both panic the hypervisor by triggering an illegal exception return (resulting in a DoS) and to redirect execution elsewhere within the hypervisor with full register control, instead of causing a return to the guest. Reference: https://www.openwall.com/lists/oss-security/2018/10/02/2 Proposed Upstream Patches: https://git.kernel.org/pub/scm/linux/kernel/git/arm64/linux.git/commit/?id=d26c25a9 https://git.kernel.org/pub/scm/linux/kernel/git/arm64/linux.git/commit/?id=2a3f9345
Created kernel tracking bugs for this issue: Affects: fedora-all [bug 1635476]
kernel-4.18.12-200.fc28, kernel-headers-4.18.12-200.fc28 has been pushed to the Fedora 28 stable repository. If problems still persist, please make note of it in this bug report.
kernel-4.18.12-100.fc27, kernel-headers-4.18.12-100.fc27 has been pushed to the Fedora 27 stable repository. If problems still persist, please make note of it in this bug report.