Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-10853

Опубликовано: 11 сент. 2018
Источник: debian
EPSS Низкий

Описание

A flaw was found in the way Linux kernel KVM hypervisor before 4.18 emulated instructions such as sgdt/sidt/fxsave/fxrstor. It did not check current privilege(CPL) level while emulating unprivileged instructions. An unprivileged guest user/process could use this flaw to potentially escalate privileges inside guest.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
linuxfixed4.16.16-1package
linuxfixed4.9.110-1stretchpackage

Примечания

  • Fixed by: https://git.kernel.org/linus/3c9fa24ca7c9c47605672916491f79e8ccacb9e6

EPSS

Процентиль: 15%
0.00049
Низкий

Связанные уязвимости

CVSS3: 7
ubuntu
почти 7 лет назад

A flaw was found in the way Linux kernel KVM hypervisor before 4.18 emulated instructions such as sgdt/sidt/fxsave/fxrstor. It did not check current privilege(CPL) level while emulating unprivileged instructions. An unprivileged guest user/process could use this flaw to potentially escalate privileges inside guest.

CVSS3: 7
redhat
около 7 лет назад

A flaw was found in the way Linux kernel KVM hypervisor before 4.18 emulated instructions such as sgdt/sidt/fxsave/fxrstor. It did not check current privilege(CPL) level while emulating unprivileged instructions. An unprivileged guest user/process could use this flaw to potentially escalate privileges inside guest.

CVSS3: 7
nvd
почти 7 лет назад

A flaw was found in the way Linux kernel KVM hypervisor before 4.18 emulated instructions such as sgdt/sidt/fxsave/fxrstor. It did not check current privilege(CPL) level while emulating unprivileged instructions. An unprivileged guest user/process could use this flaw to potentially escalate privileges inside guest.

suse-cvrf
почти 7 лет назад

Security update for the Linux Kernel (Live Patch 24 for SLE 12 SP2)

CVSS3: 7.8
github
около 3 лет назад

A flaw was found in the way Linux kernel KVM hypervisor before 4.18 emulated instructions such as sgdt/sidt/fxsave/fxrstor. It did not check current privilege(CPL) level while emulating unprivileged instructions. An unprivileged guest user/process could use this flaw to potentially escalate privileges inside guest.

EPSS

Процентиль: 15%
0.00049
Низкий