CVE-2018-1087 is a high-severity vulnerability affecting the Linux kernel's KVM hypervisor in versions prior to 4.16, 4.16-rc7, 4.17-rc1, 4.17-rc2, and 4.17-rc3, impacting Canonical, Debian, Linux, and Red Hat distributions. The flaw stems from improper handling of exceptions delivered after a stack switch operation, specifically with Mov SS or Pop SS instructions. This allows an unprivileged KVM guest user to crash the guest or potentially escalate privileges within it. While no active exploits or public exploit code are known, the vulnerability has garnered some community discussion and media coverage, indicating awareness of its potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.16CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:4.16:*:*:*:*:*:*:* | ||
4.16CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:4.16:rc7:*:*:*:*:*:* | ||
4.17CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:4.17:rc1:*:*:*:*:*:* | ||
4.17CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:4.17:rc2:*:*:*:*:*:* | ||
4.17CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:4.17:rc3:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.