UBUNTU-CVE-2018-18021
arch/arm64/kvm/guest.c in KVM in the Linux kernel before 4.18.12 on the arm64 platform mishandles the KVM_SET_ON_REG ioctl. This is exploitable by attackers who can create virtual machines. An attacker can arbitrarily redirect the hypervisor flow of control (with full register control). An attacker can also cause a denial of service (hypervisor panic) via an illegal exception return. This occurs because of insufficient restrictions on userspace access to the core register file, and because PSTATE.M validation does not prevent unintended execution modes.
02 / AFFECTED SOFTWARE
Affected packages
61 explicit affected versions
83 explicit affected versions
4 explicit affected versions
47 explicit affected versions
3 explicit affected versions
55 explicit affected versions
53 explicit affected versions
26 explicit affected versions
3 explicit affected versions
22 explicit affected versions
26 explicit affected versions
51 explicit affected versions
6 explicit affected versions
12 explicit affected versions
1 explicit affected versions
1 explicit affected versions
23 explicit affected versions
7 explicit affected versions
7 explicit affected versions
8 explicit affected versions
7 explicit affected versions
1 explicit affected versions
191 explicit affected versions
3 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
arch/arm64/kvm/guest.c in KVM in the Linux kernel before 4.18.12 on the arm64 platform mishandles the KVM_SET_ON_REG ioctl. This is exploitable by attackers who can create virtual machines. An attacker can arbitrarily redirect the hypervisor flow of control (with full register control). An attacker can also cause a denial of service (hypervisor panic) via an illegal exception return. This occurs because of insufficient restrictions on userspace access to the core register file, and because PSTATE.M validation does not prevent unintended execution modes.
05 / REFERENCES
Further evidence
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=2a3f93459d689d990b3ecfbe782fec89b97d3279
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=d26c25a9d19b5976b319af528886f89cf455692d
- https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.18.12
- https://git.kernel.org/linus/2a3f93459d689d990b3ecfbe782fec89b97d3279
- https://git.kernel.org/linus/d26c25a9d19b5976b319af528886f89cf455692d
- https://github.com/torvalds/linux/commit/2a3f93459d689d990b3ecfbe782fec89b97d3279
- https://github.com/torvalds/linux/commit/d26c25a9d19b5976b319af528886f89cf455692d
- https://ubuntu.com/security/CVE-2018-18021
- https://ubuntu.com/security/notices/USN-3821-1
- https://ubuntu.com/security/notices/USN-3821-2
- https://ubuntu.com/security/notices/USN-3931-1
- https://ubuntu.com/security/notices/USN-3931-2
- https://www.cve.org/CVERecord?id=CVE-2018-18021
- https://www.openwall.com/lists/oss-security/2018/10/02/2