USN-3484-3: Linux kernel (GCP) vulnerability
It was discovered that the KVM subsystem in the Linux kernel did not properly keep track of nested levels in guest page tables. A local attacker in a guest VM could use this to cause a denial of service (host OS crash) or possibly execute arbitrary code in the host OS.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Linux kernel vulnerability?
The vulnerability ID for this Linux kernel vulnerability is USN-3484-3.
What is the impact of this vulnerability?
This vulnerability can cause a denial of service (host OS crash) or potentially allow an attacker to execute arbitrary code in the host OS.
How can a local attacker exploit this vulnerability?
A local attacker in a guest VM can exploit this vulnerability by improperly keeping track of nested levels in guest page tables.
Which version of the Linux kernel is affected by this vulnerability?
The Linux kernel version 4.10.0-1009-gcp is affected by this vulnerability.
How can I fix this vulnerability?
To fix this vulnerability, you should update to Linux kernel version 4.10.0-1009.9 or higher.