Hide Forgot
A flaw was found in the Linux kernels implementation of i1915 kvm passthrough. Systems configured with "Intel i915 graphics cards" passthrough for kvm guests suffer from a flaw in the kernel may allow a KVM guest to be able to crash the system or potentially enable priviledge escalation on the host. Upstream patch: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/drivers/gpu/drm/i915/gvt/kvmgt.c?id=51b00d8509dc69c98740da2ad07308b630d3eb7d
Created kernel tracking bugs for this issue: Affects: fedora-all [bug 1710406]
External References: https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00249.html
This was fixed for Fedora with the 5.0 series stable rebase.
Notes: :- This only affects users who have configured i915 device passthrough. :- i915 passthrough is NOT default for virtual guests configured. :- admins will likely need to explicitly configure this passthrough for use. :- I can't see how the exploitable code gets called if you have no kvm-passthrough configured. Blacklisting the kvmgt.ko kernel module may prevent the exploitable code from loading, but it will also stop the passthrough feature for i915 devices from working correctly.
I choose to rate this as IMPORTANT fix for those customers who are affected. There is a very good chance that most people using virtualization do NOT pass through the i915 hardware but for those that have, this should be fixed.
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2019:1873 https://access.redhat.com/errata/RHSA-2019:1873
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2019:1891 https://access.redhat.com/errata/RHSA-2019:1891
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2019-11085
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2019:1959 https://access.redhat.com/errata/RHSA-2019:1959
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2019:1971 https://access.redhat.com/errata/RHSA-2019:1971
This issue has been addressed in the following products: Red Hat Enterprise Linux 7.5 Extended Update Support Via RHSA-2020:0543 https://access.redhat.com/errata/RHSA-2020:0543
This issue has been addressed in the following products: Red Hat Enterprise Linux 7.4 Advanced Update Support Red Hat Enterprise Linux 7.4 Update Services for SAP Solutions Red Hat Enterprise Linux 7.4 Telco Extended Update Support Via RHSA-2020:0592 https://access.redhat.com/errata/RHSA-2020:0592
This issue has been addressed in the following products: Red Hat Enterprise MRG 2 Via RHSA-2020:0609 https://access.redhat.com/errata/RHSA-2020:0609