7.8
CVE-2017-7518
- EPSS 0.67%
- Veröffentlicht 30.07.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:32:03
- Erkennungen
A flaw was found in the Linux kernel before version 4.12 in the way the KVM module processed the trap flag(TF) bit in EFLAGS during emulation of the syscall instruction, which leads to a debug exception(#DB) being raised in the guest stack. A user/process inside a guest could use this flaw to potentially escalate their privileges inside the guest. Linux guests are not affected by this.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Redhat ≫ Enterprise Linux Version 7.0
Redhat ≫ Enterprise Linux Desktop Version 7.0
Redhat ≫ Enterprise Linux Server Version 7.0
Redhat ≫ Enterprise Linux Server Aus Version 7.4
Redhat ≫ Enterprise Linux Server Eus Version 7.4
Redhat ≫ Enterprise Linux Server Eus Version 7.5
Redhat ≫ Enterprise Linux Workstation Version 7.0
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition lts
Debian ≫ Debian Linux Version 8.0
Debian ≫ Debian Linux Version 9.0
Linux ≫ Linux Kernel Version < 4.12
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.67% | 0.483 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.8 | 1.8 | 5.9 |
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 4.6 | 3.9 | 6.4 |
AV:L/AC:L/Au:N/C:P/I:P/A:P
|
| RedHat | 5.5 | 2.1 | 3.4 |
CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
|
CWE-250 Execution with Unnecessary Privileges
The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.
CWE-755 Improper Handling of Exceptional Conditions
The product does not handle or incorrectly handles an exceptional condition.
https://usn.ubuntu.com/3754-1/
https://usn.ubuntu.com/3619-1/
https://usn.ubuntu.com/3619-2/
https://access.redhat.com/errata/RHSA-2018:0395
https://access.redhat.com/errata/RHSA-2018:0412
https://www.debian.org/security/2017/dsa-3981
http://www.openwall.com/lists/oss-security/2017/06/23/5
http://www.securityfocus.com/bid/99263
http://www.securitytracker.com/id/1038782
https://access.redhat.com/articles/3290921
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-7518
https://www.spinics.net/lists/kvm/msg151817.html