7.8
CVE-2018-1087
- EPSS 0.77%
- Veröffentlicht 15.05.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:09
- Erkennungen
kernel KVM before versions kernel 4.16, kernel 4.16-rc7, kernel 4.17-rc1, kernel 4.17-rc2 and kernel 4.17-rc3 is vulnerable to a flaw in the way the Linux kernel's KVM hypervisor handled exceptions delivered after a stack switch operation via Mov SS or Pop SS instructions. During the stack switch operation, the processor did not deliver interrupts and exceptions, rather they are delivered once the first instruction after the stack switch is executed. An unprivileged KVM guest user could use this flaw to crash the guest or, potentially, escalate their privileges in the guest.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version 4.16
Linux ≫ Linux Kernel Version 4.16 Update rc7
Linux ≫ Linux Kernel Version 4.17 Update rc1
Linux ≫ Linux Kernel Version 4.17 Update rc2
Linux ≫ Linux Kernel Version 4.17 Update rc3
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 17.10
Debian ≫ Debian Linux Version 8.0
Debian ≫ Debian Linux Version 9.0
Redhat ≫ Enterprise Linux Version 7.0
Redhat ≫ Enterprise Linux Desktop Version 7.0
Redhat ≫ Enterprise Linux Server Version 7.0
Redhat ≫ Enterprise Linux Server Aus Version 7.2
Redhat ≫ Enterprise Linux Server Aus Version 7.3
Redhat ≫ Enterprise Linux Server Aus Version 7.4
Redhat ≫ Enterprise Linux Server Eus Version 7.3
Redhat ≫ Enterprise Linux Server Eus Version 7.4
Redhat ≫ Enterprise Linux Server Eus Version 7.5
Redhat ≫ Enterprise Linux Server Tus Version 7.2
Redhat ≫ Enterprise Linux Server Tus Version 7.3
Redhat ≫ Enterprise Linux Server Tus Version 7.4
Redhat ≫ Enterprise Linux Virtualization Version 4.0
Redhat ≫ Enterprise Linux Workstation Version 7.0
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.77% | 0.509 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.8 | 1.8 | 5.9 |
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 4.6 | 3.9 | 6.4 |
AV:L/AC:L/Au:N/C:P/I:P/A:P
|
| RedHat | 8 | 2.1 | 5.9 |
CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-250 Execution with Unnecessary Privileges
The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.
https://access.redhat.com/errata/RHSA-2018:1318
https://access.redhat.com/errata/RHSA-2018:1355
https://access.redhat.com/errata/RHSA-2018:1524
https://access.redhat.com/errata/RHSA-2018:1345
https://access.redhat.com/errata/RHSA-2018:1347
https://access.redhat.com/errata/RHSA-2018:1348
https://usn.ubuntu.com/3641-1/
https://usn.ubuntu.com/3641-2/
https://www.debian.org/security/2018/dsa-4196
http://www.openwall.com/lists/oss-security/2018/05/08/5
http://www.securityfocus.com/bid/104127
http://www.securitytracker.com/id/1040862
https://access.redhat.com/security/vulnerabilities/pop_ss
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1087