summaryrefslogtreecommitdiffstats
path: root/retired/CVE-2018-16882
diff options
context:
space:
mode:
authorSalvatore Bonaccorso <carnil@debian.org>2019-01-31 09:05:15 +0100
committerSalvatore Bonaccorso <carnil@debian.org>2019-01-31 09:05:15 +0100
commitab6102ffbf06f5d2f0a5bb07c590a52169a669a1 (patch)
tree1a61118ac00842fc9f533a05748a5131f264486d /retired/CVE-2018-16882
parent8f6a8478f0ed7389e17dad043a2b9e268573d7f5 (diff)
Retire CVE-2018-16882
Diffstat (limited to 'retired/CVE-2018-16882')
-rw-r--r--retired/CVE-2018-1688215
1 files changed, 15 insertions, 0 deletions
diff --git a/retired/CVE-2018-16882 b/retired/CVE-2018-16882
new file mode 100644
index 00000000..d676c998
--- /dev/null
+++ b/retired/CVE-2018-16882
@@ -0,0 +1,15 @@
+Description: KVM: nVMX: use after free in posted interrupt processing
+References:
+ https://www.openwall.com/lists/oss-security/2018/12/18/6
+ https://marc.info/?l=kvm&m=154514994222809&w=2
+Notes:
+ carnil> Commit fixes 5e2f30b756a37 "KVM: nVMX: get rid of nested_get_page()"
+ carnil> needs to check if issue only introduced post/with 4.14-rc1.
+Bugs:
+upstream: released (4.20) [c2dd5146e9fe1f22c77c1b011adf84eea0245806]
+4.19-upstream-stable: released (4.19.13) [1972ca04708330b0edd52956e644e3974065a613]
+4.9-upstream-stable: N/A "Vulnerable code introduced later"
+3.16-upstream-stable: N/A "Vulnerable code introduced later"
+sid: released (4.19.13-1)
+4.9-stretch-security: N/A "Vulnerable code not present"
+3.16-jessie-security: N/A "Vulnerable code not present"

© 2014-2024 Faster IT GmbH | imprint | privacy policy