UBUNTU-CVE-2018-16882
A use-after-free issue was found in the way the Linux kernel's KVM hypervisor processed posted interrupts when nested(=1) virtualization is enabled. In nested_get_vmcs12_pages(), in case of an error while processing posted interrupt address, it unmaps the 'pi_desc_page' without resetting 'pi_desc' descriptor address, which is later used in pi_test_and_clear_on(). A guest user/process could use this flaw to crash the host kernel resulting in DoS or potentially gain privileged access to a system. Kernel versions before 4.14.91 and before 4.19.13 are vulnerable.
02 / AFFECTED SOFTWARE
Affected packages
6 explicit affected versions
2 explicit affected versions
29 explicit affected versions
25 explicit affected versions
45 explicit affected versions
1 explicit affected versions
23 explicit affected versions
18 explicit affected versions
20 explicit affected versions
17 explicit affected versions
2 explicit affected versions
1 explicit affected versions
18 explicit affected versions
15 explicit affected versions
1 explicit affected versions
20 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
A use-after-free issue was found in the way the Linux kernel's KVM hypervisor processed posted interrupts when nested(=1) virtualization is enabled. In nested_get_vmcs12_pages(), in case of an error while processing posted interrupt address, it unmaps the 'pi_desc_page' without resetting 'pi_desc' descriptor address, which is later used in pi_test_and_clear_on(). A guest user/process could use this flaw to crash the host kernel resulting in DoS or potentially gain privileged access to a system. Kernel versions before 4.14.91 and before 4.19.13 are vulnerable.
05 / REFERENCES
Further evidence
- https://marc.info/?l=kvm&m=154514994222809&w=2
- https://ubuntu.com/security/CVE-2018-16882
- https://ubuntu.com/security/notices/USN-3871-1
- https://ubuntu.com/security/notices/USN-3871-3
- https://ubuntu.com/security/notices/USN-3871-4
- https://ubuntu.com/security/notices/USN-3871-5
- https://ubuntu.com/security/notices/USN-3872-1
- https://ubuntu.com/security/notices/USN-3878-1
- https://ubuntu.com/security/notices/USN-3878-2
- https://www.cve.org/CVERecord?id=CVE-2018-16882
- https://www.openwall.com/lists/oss-security/2018/12/18/6