A flaw was found in Linux kernel's KVM virtualization subsystem. The VMX code does not restore the GDT.LIMIT to the previous host value, but instead sets it to 64KB. With a corrupted GDT limit a host's userspace code has an ability to place malicious entries in the GDT, particularly to the per-cpu variables. An attacker can use this to escalate their privileges.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
No history.
Information
Published : 2018-07-26 17:29
Updated : 2024-11-21 03:42
NVD link : CVE-2018-10901
Mitre link : CVE-2018-10901
CVE.ORG link : CVE-2018-10901
JSON object : View
Products Affected
redhat
- enterprise_linux_workstation
- enterprise_linux_server_aus
- enterprise_linux_desktop
- enterprise_linux_server
linux
- linux_kernel
CWE