Oval Definition:oval:com.ubuntu.cosmic:def:2018168820000000
Revision Date:2019-01-03Version:1
Title:CVE-2018-16882 on Ubuntu 18.10 (cosmic) - medium.
Description:A use-after-free issue was found in the way the Linux kernel's KVM hypervisor processed posted interrupts when nested(=1) virtualization is enabled. In nested_get_vmcs12_pages(), in case of an error while processing posted interrupt address, it unmaps the 'pi_desc_page' without resetting 'pi_desc' descriptor address, which is later used in pi_test_and_clear_on(). A guest user/process could use this flaw to crash the host kernel resulting in DoS or potentially gain privileged access to a system. Kernel versions before 4.14.91 and before 4.19.13 are vulnerable. Cfir Cohen discovered that a use-after-free vulnerability existed in the KVM implementation of the Linux kernel, when handling interrupts in environments where nested virtualization is in use (nested KVM virtualization is not enabled by default in Ubuntu kernels). A local attacker in a guest VM could possibly use this to gain administrative privileges in a host machine.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2018-16882
Platform(s):Ubuntu 18.10
Product(s):
Definition Synopsis
  • Ubuntu 18.10 (cosmic) is installed.
  • AND Package Information
  • linux package in cosmic was vulnerable but has been fixed (note: '4.18.0-14.15').
  • OR linux-aws package in cosmic was vulnerable but has been fixed (note: '4.18.0-1008.10').
  • OR linux-azure package in cosmic was vulnerable but has been fixed (note: '4.18.0-1008.8').
  • OR linux-gcp package in cosmic was vulnerable but has been fixed (note: '4.18.0-1006.7').
  • OR linux-kvm package in cosmic was vulnerable but has been fixed (note: '4.18.0-1007.7').
  • OR linux-meta package in cosmic was vulnerable but has been fixed (note: '4.18.0-14.15').
  • OR linux-meta-aws package in cosmic was vulnerable but has been fixed (note: '4.18.0-1008.10').
  • OR linux-meta-azure package in cosmic was vulnerable but has been fixed (note: '4.18.0-1008.8').
  • OR linux-meta-gcp package in cosmic was vulnerable but has been fixed (note: '4.18.0-1006.7').
  • OR linux-meta-kvm package in cosmic was vulnerable but has been fixed (note: '4.18.0-1007.7').
  • OR linux-meta-oem package in cosmic was vulnerable but has been fixed (note: '4.15.0-1033.38').
  • OR linux-meta-raspi2 package in cosmic was vulnerable but has been fixed (note: '4.18.0-1009.11').
  • OR linux-oem package in cosmic was vulnerable but has been fixed (note: '4.15.0-1033.38').
  • OR linux-raspi2 package in cosmic was vulnerable but has been fixed (note: '4.18.0-1009.11').
  • OR linux-signed package in cosmic was vulnerable but has been fixed (note: '4.18.0-14.15').
  • OR linux-signed-azure package in cosmic was vulnerable but has been fixed (note: '4.18.0-1008.8').
  • OR linux-signed-gcp package in cosmic was vulnerable but has been fixed (note: '4.18.0-1006.7').
  • OR linux-signed-oem package in cosmic was vulnerable but has been fixed (note: '4.15.0-1033.38').
  • BACK