UBUNTU-CVE-2018-16880
A flaw was found in the Linux kernel's handle_rx() function in the [vhost_net] driver. A malicious virtual guest, under specific conditions, can trigger an out-of-bounds write in a kmalloc-8 slab on a virtual host which may lead to a kernel memory corruption and a system panic. Due to the nature of the flaw, privilege escalation cannot be fully ruled out. Versions from v4.16 and newer are vulnerable.
02 / AFFECTED SOFTWARE
Affected packages
22 explicit affected versions
3 explicit affected versions
3 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
A flaw was found in the Linux kernel's handle_rx() function in the [vhost_net] driver. A malicious virtual guest, under specific conditions, can trigger an out-of-bounds write in a kmalloc-8 slab on a virtual host which may lead to a kernel memory corruption and a system panic. Due to the nature of the flaw, privilege escalation cannot be fully ruled out. Versions from v4.16 and newer are vulnerable.
05 / REFERENCES
Further evidence
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=b46a0bf78ad7b150ef5910da83859f7f5a514ffd
- https://ubuntu.com/security/CVE-2018-16880
- https://ubuntu.com/security/notices/USN-3903-1
- https://ubuntu.com/security/notices/USN-3903-2
- https://www.cve.org/CVERecord?id=CVE-2018-16880
- https://www.openwall.com/lists/oss-security/2019/01/25/1