[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

253164

 
 

909

 
 

197077

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

CVE-2020-8834 -- linux-image

ID: oval:org.secpod.oval:def:2004121Date: (C)2020-10-08   (M)2024-05-22
Class: VULNERABILITYFamily: unix




KVM in the Linux kernel on Power8 processors has a conflicting use of HSTATE_HOST_R1 to store r1 state in kvmppc_hv_entry plus in kvmppc_{save,restore}_tm, leading to a stack corruption. Because of this, an attacker with the ability run code in kernel space of a guest VM can cause the host kernel to panic. There were two commits that, according to the reporter, introduced the vulnerability: f024ee098476 87a11bb6a7f7 The former landed in 4.8, the latter in 4.17. This was fixed without realizing the impact in 4.18 with the following three commits, though it"s believed the first is the only strictly necessary commit: 6f597c6b63b6 7b0e827c6970 009c872a8bc4

Platform:
Debian 10.x
Product:
linux-image-4
Reference:
CVE-2020-8834
CVE    1
CVE-2020-8834
CPE    2
cpe:/a:linux:linux_image:4
cpe:/o:debian:debian_linux:10.x

© SecPod Technologies