First published: Tue Nov 21 2017(Updated: )
It was discovered that the KVM subsystem in the Linux kernel did not properly keep track of nested levels in guest page tables. A local attacker in a guest VM could use this to cause a denial of service (host OS crash) or possibly execute arbitrary code in the host OS.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/linux-image-4.10.0-1009-gcp | <4.10.0-1009.9 | 4.10.0-1009.9 |
Ubuntu gir1.2-packagekitglib-1.0 | =16.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Linux kernel vulnerability is USN-3484-3.
This vulnerability can cause a denial of service (host OS crash) or potentially allow an attacker to execute arbitrary code in the host OS.
A local attacker in a guest VM can exploit this vulnerability by improperly keeping track of nested levels in guest page tables.
The Linux kernel version 4.10.0-1009-gcp is affected by this vulnerability.
To fix this vulnerability, you should update to Linux kernel version 4.10.0-1009.9 or higher.