CVE-2018-10853

Published: 11 September 2018

A flaw was found in the way Linux kernel KVM hypervisor before 4.18 emulated instructions such as sgdt/sidt/fxsave/fxrstor. It did not check current privilege(CPL) level while emulating unprivileged instructions. An unprivileged guest user/process could use this flaw to potentially escalate privileges inside guest.

From the Ubuntu security team

Andy Lutomirski and Mika Penttilä discovered that the KVM implementation in the Linux kernel did not properly check privilege levels when emulating some instructions. An unprivileged attacker in a guest VM could use this to escalate privileges within the guest.

Priority

Medium

CVSS 3 base score: 7.8

Status

Package Release Status
linux
Launchpad, Ubuntu, Debian
Upstream
Released (4.18~rc1)
Ubuntu 18.04 LTS (Bionic Beaver)
Released (4.15.0-36.39)
Patches:
Introduced by 129a72a0d3c8e139a04512325384fe5ac119e74d
Fixed by 3c9fa24ca7c9c47605672916491f79e8ccacb9e6
linux-aws
Launchpad, Ubuntu, Debian
Upstream
Released (4.18~rc1)
Ubuntu 18.04 LTS (Bionic Beaver)
Released (4.15.0-1023.23)
linux-aws-hwe
Launchpad, Ubuntu, Debian
Upstream
Released (4.18~rc1)
Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

linux-azure
Launchpad, Ubuntu, Debian
Upstream
Released (4.18~rc1)
Ubuntu 18.04 LTS (Bionic Beaver)
Released (4.15.0-1025.26)
linux-azure-edge
Launchpad, Ubuntu, Debian
Upstream
Released (4.18~rc1)
Ubuntu 18.04 LTS (Bionic Beaver)
Released (4.15.0-1025.26)
linux-euclid
Launchpad, Ubuntu, Debian
Upstream
Released (4.18~rc1)
Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

linux-flo
Launchpad, Ubuntu, Debian
Upstream
Released (4.18~rc1)
Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

linux-gcp
Launchpad, Ubuntu, Debian
Upstream
Released (4.18~rc1)
Ubuntu 18.04 LTS (Bionic Beaver)
Released (4.15.0-1021.22)
linux-gcp-edge
Launchpad, Ubuntu, Debian
Upstream
Released (4.18~rc1)
Ubuntu 18.04 LTS (Bionic Beaver) Not vulnerable
(4.18.0-1004.5~18.04.1)
linux-gke
Launchpad, Ubuntu, Debian
Upstream
Released (4.18~rc1)
Ubuntu 18.04 LTS (Bionic Beaver) Not vulnerable

linux-goldfish
Launchpad, Ubuntu, Debian
Upstream
Released (4.18~rc1)
Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

linux-grouper
Launchpad, Ubuntu, Debian
Upstream
Released (4.18~rc1)
Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

linux-hwe
Launchpad, Ubuntu, Debian
Upstream
Released (4.18~rc1)
Ubuntu 18.04 LTS (Bionic Beaver) Not vulnerable
(4.18.0-13.14~18.04.1)
linux-hwe-edge
Launchpad, Ubuntu, Debian
Upstream
Released (4.18~rc1)
Ubuntu 18.04 LTS (Bionic Beaver) Not vulnerable
(5.0.0-14.15~18.04.1)
linux-kvm
Launchpad, Ubuntu, Debian
Upstream
Released (4.18~rc1)
Ubuntu 18.04 LTS (Bionic Beaver)
Released (4.15.0-1023.23)
linux-lts-trusty
Launchpad, Ubuntu, Debian
Upstream
Released (4.18~rc1)
Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

linux-lts-utopic
Launchpad, Ubuntu, Debian
Upstream
Released (4.18~rc1)
Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

linux-lts-vivid
Launchpad, Ubuntu, Debian
Upstream
Released (4.18~rc1)
Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

linux-lts-wily
Launchpad, Ubuntu, Debian
Upstream
Released (4.18~rc1)
Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

linux-lts-xenial
Launchpad, Ubuntu, Debian
Upstream
Released (4.18~rc1)
Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

linux-maguro
Launchpad, Ubuntu, Debian
Upstream
Released (4.18~rc1)
Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

linux-mako
Launchpad, Ubuntu, Debian
Upstream
Released (4.18~rc1)
Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

linux-manta
Launchpad, Ubuntu, Debian
Upstream
Released (4.18~rc1)
Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

linux-oem
Launchpad, Ubuntu, Debian
Upstream
Released (4.18~rc1)
Ubuntu 18.04 LTS (Bionic Beaver)
Released (4.15.0-1021.24)
linux-oracle
Launchpad, Ubuntu, Debian
Upstream
Released (4.18~rc1)
Ubuntu 18.04 LTS (Bionic Beaver) Not vulnerable
(4.15.0-1007.9)
linux-raspi2
Launchpad, Ubuntu, Debian
Upstream
Released (4.18~rc1)
Ubuntu 18.04 LTS (Bionic Beaver)
Released (4.15.0-1024.26)
linux-snapdragon
Launchpad, Ubuntu, Debian
Upstream
Released (4.18~rc1)
Ubuntu 18.04 LTS (Bionic Beaver)
Released (4.15.0-1053.57)