Improper check or handling of exceptional conditions in Linux kernel - CVE-2018-1087

 

Improper check or handling of exceptional conditions in Linux kernel - CVE-2018-1087

Published: May 10, 2018


Vulnerability identifier: #VU12520
CSH Severity: Low
CVSS v4: 8.7 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-1087
CWE-ID: CWE-703
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an adjacent attacker to cause DoS condition or gain elevated privileges on the target system.

The weakness exists in the Linux kernel KVM hypervisor due to improper handling of debug exceptions delivered after a stack switch operation via mov SS or pop SS instructions. During the stack switch operation, the exceptions are deferred. An adjacent attacker can cause the service to crash or gain root privileges.

Affected software

Linux kernel
Debian Linux
Amazon Linux AMI
Red Hat Enterprise Linux for Real Time
Red Hat Enterprise Linux for Real Time for NFV
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux Server - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, big endian - Extended Update Support
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
SUSE Linux

android-emulator-hypervisor-driver-for-amd-processors
kernel (Red Hat package)
kernel-rt (Red Hat package)
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
Red Hat Virtualization Host
Red Hat Virtualization

How to mitigate CVE-2018-1087

Update to version 4.16-rc7.

android-emulator-hypervisor-driver-for-amd-processors - update to 2.2
kernel (Red Hat package) - addressed in versions 3.10.0-327.66.3.el7, 3.10.0-514.48.3.el7, 3.10.0-693.25.4.el7
kernel-rt (Red Hat package) - update to 3.10.0-862.2.3.rt56.806.el7

External References

Related Security Bulletins