From ab6102ffbf06f5d2f0a5bb07c590a52169a669a1 Mon Sep 17 00:00:00 2001 From: Salvatore Bonaccorso Date: Thu, 31 Jan 2019 09:05:15 +0100 Subject: Retire CVE-2018-16882 --- retired/CVE-2018-16882 | 15 +++++++++++++++ 1 file changed, 15 insertions(+) create mode 100644 retired/CVE-2018-16882 (limited to 'retired/CVE-2018-16882') diff --git a/retired/CVE-2018-16882 b/retired/CVE-2018-16882 new file mode 100644 index 000000000..d676c9986 --- /dev/null +++ b/retired/CVE-2018-16882 @@ -0,0 +1,15 @@ +Description: KVM: nVMX: use after free in posted interrupt processing +References: + https://www.openwall.com/lists/oss-security/2018/12/18/6 + https://marc.info/?l=kvm&m=154514994222809&w=2 +Notes: + carnil> Commit fixes 5e2f30b756a37 "KVM: nVMX: get rid of nested_get_page()" + carnil> needs to check if issue only introduced post/with 4.14-rc1. +Bugs: +upstream: released (4.20) [c2dd5146e9fe1f22c77c1b011adf84eea0245806] +4.19-upstream-stable: released (4.19.13) [1972ca04708330b0edd52956e644e3974065a613] +4.9-upstream-stable: N/A "Vulnerable code introduced later" +3.16-upstream-stable: N/A "Vulnerable code introduced later" +sid: released (4.19.13-1) +4.9-stretch-security: N/A "Vulnerable code not present" +3.16-jessie-security: N/A "Vulnerable code not present" -- cgit v1.2.3