CVE-2017-7518: High severity redhat Enterprise Linux vulnerability
A flaw was found in the Linux kernel before version 4.12 in the way the KVM module processed the trap flag(TF) bit in EFLAGS during emulation of the syscall instruction, which leads to a debug exception(#DB) being raised in the guest stack. A user/process inside a guest could use this flaw to potentially escalate their privileges inside the guest. Linux guests are not affected by this.
Other sources
Linux kernel built with the Kernel-based Virtual Machine(CONFIGKVM) support is vulnerable to an incorrect debug exception(#DB) error. It could occur while emulating a syscall instruction.
A user/process inside guest could use this flaw to potentially escalate their privileges inside guest.
Note: Linux guests are not affected.
Upstream patch: --------------- -> https://www.spinics.net/lists/kvm/msg151817.html
Reference: ---------- -> https://xenbits.xen.org/xsa/advisory-204.html -> https://www.spinics.net/lists/kvm/msg151819.html -> http://www.openwall.com/lists/oss-security/2017/06/23/5 -> https://access.redhat.com/articles/3290921
— Red Hat
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2017-7518?
CVE-2017-7518 is a vulnerability found in the Linux kernel before version 4.12 that affects the KVM module.
What is the severity of CVE-2017-7518?
CVE-2017-7518 has a severity level of medium.
Which Linux kernel versions are affected by CVE-2017-7518?
Linux kernel versions before 4.12 are affected by CVE-2017-7518.
How can CVE-2017-7518 be exploited?
CVE-2017-7518 can be exploited by a user or process inside a guest using the trap flag (TF) bit in EFLAGS during the emulation of the syscall instruction.
Is there a fix available for CVE-2017-7518?
Yes, the fix for CVE-2017-7518 is available in the Linux kernel version 4.12 and later.