All errata/sisyphus/ALT-PU-2018-1982-1
ALT-PU-2018-1982-1

Package update kernel-image-std-pae in branch sisyphus

Version4.4.139-alt1
Published2018-07-05
Max severityHIGH
Severity:

Closed issues (1)

CVE-2018-10853
HIGH7.8

A flaw was found in the way Linux kernel KVM hypervisor before 4.18 emulated instructions such as sgdt/sidt/fxsave/fxrstor. It did not check current privilege(CPL) level while emulating unprivileged instructions. An unprivileged guest user/process could use this flaw to potentially escalate privileges inside guest.

Published: 2018-09-11Modified: 2024-11-21
CVSS 2.0MEDIUM 4.6
CVSS:2.0/AV:L/AC:L/Au:N/C:P/I:P/A:P
CVSS 3.xHIGH 7.8
CVSS:3.x/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
References