A use-after-free issue was found in the way the Linux kernel's KVM hypervisor processed posted interrupts when nested(=1) virtualization is enabled. In nested_get_vmcs12_pages(), in case of an error while processing posted interrupt address, it unmaps the 'pi_desc_page' without resetting 'pi_desc' descriptor address, which is later used in pi_test_and_clear_on(). A guest user/process could use this flaw to crash the host kernel resulting in DoS or potentially gain privileged access to a system. Kernel versions before 4.14.91 and before 4.19.13 are vulnerable.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
- CVSS 3.0 Base Score: 6.1
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:L/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Jul 30, 2024 | Jan 3, 2019 |
| Oracle_linux | — | Upgrade kernel-uek | Jul 21, 2020 | Dec 18, 2018 |
| Suse | — | Upgrade kernel-defaultUpgrade dlm-kmp-defaultUpgrade ocfs2-kmp-default | Dec 7, 2021 | Jan 3, 2019 |
| Ubuntu | — | Upgrade linux-image-awsUpgrade linux-image-4.18.0-1007-kvmUpgrade linux-image-generic-hwe-16.04Upgrade linux-image-4.15.0-44-snapdragonUpgrade linux-image-kvmUpgrade linux-image-4.18.0-14-snapdragonUpgrade linux-image-generic-lpae-hwe-16.04Upgrade linux-image-raspi2Upgrade linux-image-gcpUpgrade linux-image-4.18.0-14-generic-lpaeUpgrade linux-image-azureUpgrade linux-image-generic-hwe-18.04Upgrade linux-image-4.15.0-1037-azureUpgrade linux-image-4.18.0-1006-gcpUpgrade linux-image-4.15.0-45-generic-lpaeUpgrade linux-image-4.15.0-45-genericUpgrade linux-image-aws-hweUpgrade linux-image-4.15.0-1031-raspi2Upgrade linux-image-4.18.0-1008-azureUpgrade linux-image-generic-lpae-hwe-18.04Upgrade linux-image-lowlatency-hwe-18.04Upgrade linux-image-4.18.0-1008-awsUpgrade linux-image-genericUpgrade linux-image-lowlatency-hwe-16.04Upgrade linux-image-4.15.0-1029-kvmUpgrade linux-image-gkeUpgrade linux-image-virtual-hwe-16.04Upgrade linux-image-oemUpgrade linux-image-4.15.0-45-lowlatencyUpgrade linux-image-4.15.0-1033-oemUpgrade linux-image-4.15.0-1032-awsUpgrade linux-image-4.15.0-44-lowlatencyUpgrade linux-image-lowlatencyUpgrade linux-image-snapdragon-hwe-18.04Upgrade linux-image-4.18.0-1009-raspi2Upgrade linux-image-4.18.0-14-genericUpgrade linux-image-4.15.0-1027-gcpUpgrade linux-image-4.18.0-14-lowlatencyUpgrade linux-image-4.15.0-44-generic-lpaeUpgrade linux-image-4.15.0-44-genericUpgrade linux-image-snapdragonUpgrade linux-image-generic-lpae | Feb 5, 2019 | Jan 3, 2019 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Jan 3, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub