Privilege escalation in Linux kernel - CVE-2018-10901
Published: August 2, 2018
Vulnerability details
The vulnerability allows a local attacker to gain elevated privileges on the target system.
The vulnerability existsin the Kernel-based Virtual Machine (KVM) virtualization subsystem due to the vmx.c source code file of the affected software fails to set the GDT.LIMIT value to the previous host value and instead sets it to 64 KB. A local attacker can place malicious entries in the Global Descriptor Table (GDT), submit a specially crafted request that submits malicious input and gain elevated privileges on the system.
Affected software
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux Server - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, big endian - Extended Update Support
Red Hat Enterprise Linux EUS Compute Node
kernel (Red Hat package)
How to mitigate CVE-2018-10901
External References
Related Security Bulletins
- Multiple vulnerabilities in Linux Kernel
- Red Hat Enterprise Linux 6 update for kernel
- Red Hat Enterprise Linux 6.6 Advanced Update Support and Red Hat Enterprise Linux 6.6 Telco Extended Update Support update for kernel
- Red Hat Enterprise Linux 6.5 Advanced Update Support update for kernel
- Red Hat Enterprise Linux 6.4 Advanced Update Support update for kernel
- Red Hat Enterprise Linux 6.7 Extended Update Support update for kernel