UBUNTU-CVE-2018-18021

    Dashboard / Vulnerabilities / UBUNTU-CVE-2018-18021

    UBUNTU-CVE-2018-18021

    Published: 7 Oct 2018Last Modified: 18 Aug 2026
    Upstream:
    Aliases:

    Summary:

    Details: arch/arm64/kvm/guest.c in KVM in the Linux kernel before 4.18.12 on the arm64 platform mishandles the KVM_SET_ON_REG ioctl. This is exploitable by attackers who can create virtual machines. An attacker can arbitrarily redirect the hypervisor flow of control (with full register control). An attacker can also cause a denial of service (hypervisor panic) via an illegal exception return. This occurs because of insufficient restrictions on userspace access to the core register file, and because PSTATE.M validation does not prevent unintended execution modes.

    Affected packages

    Package

    Name: linux-lts-xenial

    Purl: pkg:deb/ubuntu/linux-lts-xenial?arch=source&distro=trusty

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -4.4.0-139.165~14.04.1

    Affected versions

    4.4.0-13.29~14.04.1
    4.4.0-14.30~14.04.2
    4.4.0-15.31~14.04.1
    4.4.0-18.34~14.04.1
    4.4.0-21.37~14.04.1
    4.4.0-22.39~14.04.1
    4.4.0-22.40~14.04.1
    4.4.0-24.43~14.04.1
    4.4.0-28.47~14.04.1
    4.4.0-31.50~14.04.1
    4.4.0-34.53~14.04.1
    4.4.0-36.55~14.04.1
    4.4.0-38.57~14.04.1
    4.4.0-42.62~14.04.1
    4.4.0-45.66~14.04.1
    4.4.0-47.68~14.04.1
    4.4.0-51.72~14.04.1
    4.4.0-53.74~14.04.1
    4.4.0-57.78~14.04.1
    4.4.0-59.80~14.04.1
    4.4.0-62.83~14.04.1
    4.4.0-63.84~14.04.2
    4.4.0-64.85~14.04.1
    4.4.0-66.87~14.04.1
    4.4.0-67.88~14.04.1
    4.4.0-70.91~14.04.1
    4.4.0-71.92~14.04.1
    4.4.0-72.93~14.04.1
    4.4.0-75.96~14.04.1
    4.4.0-78.99~14.04.2
    4.4.0-79.100~14.04.1
    4.4.0-81.104~14.04.1
    4.4.0-83.106~14.04.1
    4.4.0-87.110~14.04.1
    4.4.0-89.112~14.04.1
    4.4.0-91.114~14.04.1
    4.4.0-92.115~14.04.1
    4.4.0-93.116~14.04.1
    4.4.0-96.119~14.04.1
    4.4.0-97.120~14.04.1
    4.4.0-98.121~14.04.1
    4.4.0-101.124~14.04.1
    4.4.0-103.126~14.04.1
    4.4.0-104.127~14.04.1
    4.4.0-108.131~14.04.1
    4.4.0-109.132~14.04.1
    4.4.0-111.134~14.04.1
    4.4.0-112.135~14.04.1
    4.4.0-116.140~14.04.1
    4.4.0-119.143~14.04.1
    4.4.0-121.145~14.04.1
    4.4.0-124.148~14.04.1
    4.4.0-127.153~14.04.1
    4.4.0-128.154~14.04.1
    4.4.0-130.156~14.04.1
    4.4.0-131.157~14.04.1
    4.4.0-133.159~14.04.1
    4.4.0-134.160~14.04.1
    4.4.0-135.161~14.04.1
    4.4.0-137.163~14.04.1
    4.4.0-138.164~14.04.1

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High