A flaw was found in Linux kernel's KVM virtualization subsystem. The VMX code does not restore the GDT.LIMIT to the previous host value, but instead sets it to 64KB. With a corrupted GDT limit a host's userspace code has an ability to place malicious entries in the GDT, particularly to the per-cpu variables. An attacker can use this to escalate their privileges.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2018-10901.json"
[
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@3444d7da1839b851eefedd372978d8a982316c36",
"signature_type": "Function",
"digest": {
"function_hash": "55694496545985944467646918385756370070",
"length": 638.0
},
"deprecated": false,
"target": {
"file": "arch/x86/kvm/vmx.c",
"function": "hardware_enable"
},
"id": "CVE-2018-10901-13b1b008",
"signature_version": "v1"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@3444d7da1839b851eefedd372978d8a982316c36",
"signature_type": "Line",
"digest": {
"line_hashes": [
"93943198105979181761504830764382793382",
"174025164244992563200420467819104210004",
"283793088260529092172393693517645084440",
"154281900667720567647291390121300444570",
"9340607226300760769403900739320783447",
"219901352412696155455447002335505731052",
"133554096657483567859446064684062810499",
"312166212690558985256653458799005403838",
"274103898682530110634124586550211312048",
"79879426170861155621034545578271861466",
"119424593322074397841077836129733112516"
],
"threshold": 0.9
},
"deprecated": false,
"target": {
"file": "arch/x86/kvm/vmx.c"
},
"id": "CVE-2018-10901-749686ae",
"signature_version": "v1"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@3444d7da1839b851eefedd372978d8a982316c36",
"signature_type": "Function",
"digest": {
"function_hash": "246213126339533771709000550758240324729",
"length": 830.0
},
"deprecated": false,
"target": {
"file": "arch/x86/kvm/vmx.c",
"function": "__vmx_load_host_state"
},
"id": "CVE-2018-10901-bdb04500",
"signature_version": "v1"
}
]