A flaw was found in Linux kernel's KVM virtualization subsystem. The VMX code does not restore the GDT.LIMIT to the previous host value, but instead sets it to 64KB. With a corrupted GDT limit a host's userspace code has an ability to place malicious entries in the GDT, particularly to the per-cpu variables. An attacker can use this to escalate their privileges.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade python-perf-debuginfoUpgrade python-perfUpgrade kernel-debuginfo-common-x86_64Upgrade kernel-toolsUpgrade kernel-headersUpgrade perfUpgrade kernel-tools-debuginfoUpgrade kernel-debuginfoUpgrade kernel-tools-develUpgrade perf-debuginfoUpgrade kernel-develUpgrade kernel | Apr 27, 2020 | Jul 26, 2018 |
| Amazon_linux | — | Upgrade kernel | Sep 7, 2018 | May 25, 2018 |
| Centos_linux | — | Upgrade kernel | Aug 16, 2018 | Jul 26, 2018 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Jan 31, 2019 |
| Oracle_linux | — | Upgrade kernel | Aug 15, 2018 | Aug 2, 2010 |
| Redhat_linux | — | Upgrade kernel | Aug 15, 2018 | Jul 26, 2018 |
| Ubuntu | — | Upgrade linux-hwe-edge | Nov 19, 2024 | Jul 26, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub