KVM in the Linux kernel before 4.8.12, when I/O APIC is enabled, does not properly restrict the VCPU index, which allows guest OS users to gain host OS privileges or cause a denial of service (out-of-bounds array access and host OS crash) via a crafted interrupt request, related to arch/x86/kvm/ioapic.c and arch/x86/kvm/ioapic.h.
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "block-modules-4.8.0-39-generic-di" }, { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "block-modules-4.8.0-39-generic-lpae-di" }, { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "crypto-modules-4.8.0-39-generic-di" }, { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "crypto-modules-4.8.0-39-generic-lpae-di" }, { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "dasd-extra-modules-4.8.0-39-generic-di" }, { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "dasd-modules-4.8.0-39-generic-di" }, { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "fat-modules-4.8.0-39-generic-di" }, { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "fat-modules-4.8.0-39-generic-lpae-di" }, { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "fb-modules-4.8.0-39-generic-di" }, { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "firewire-core-modules-4.8.0-39-generic-di" }, { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "floppy-modules-4.8.0-39-generic-di" }, { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "fs-core-modules-4.8.0-39-generic-di" }, { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "fs-core-modules-4.8.0-39-generic-lpae-di" }, { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "fs-secondary-modules-4.8.0-39-generic-di" }, { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "fs-secondary-modules-4.8.0-39-generic-lpae-di" }, { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "input-modules-4.8.0-39-generic-di" }, { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "input-modules-4.8.0-39-generic-lpae-di" }, { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "ipmi-modules-4.8.0-39-generic-di" }, { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "ipmi-modules-4.8.0-39-generic-lpae-di" }, { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "irda-modules-4.8.0-39-generic-di" }, { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "irda-modules-4.8.0-39-generic-lpae-di" }, { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "kernel-image-4.8.0-39-generic-di" }, { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "kernel-image-4.8.0-39-generic-lpae-di" }, { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "linux-cloud-tools-4.8.0-39-generic" }, { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "linux-cloud-tools-4.8.0-39-lowlatency" }, { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "linux-headers-4.8.0-39" }, { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "linux-headers-4.8.0-39-generic" }, { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "linux-headers-4.8.0-39-generic-lpae" }, { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "linux-headers-4.8.0-39-lowlatency" }, { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "linux-hwe-cloud-tools-4.8.0-39" }, { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "linux-hwe-cloud-tools-4.8.0-39-dbgsym" }, { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "linux-hwe-tools-4.8.0-39" }, { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "linux-hwe-tools-4.8.0-39-dbgsym" }, { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "linux-hwe-udebs-generic" }, { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "linux-hwe-udebs-generic-lpae" }, { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "linux-image-4.8.0-39-generic" }, { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "linux-image-4.8.0-39-generic-dbgsym" }, { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "linux-image-4.8.0-39-generic-lpae" }, { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "linux-image-4.8.0-39-generic-lpae-dbgsym" }, { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "linux-image-4.8.0-39-lowlatency" }, { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "linux-image-4.8.0-39-lowlatency-dbgsym" }, { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "linux-image-extra-4.8.0-39-generic" }, { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "linux-source-4.8.0" }, { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "linux-tools-4.8.0-39-generic" }, { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "linux-tools-4.8.0-39-generic-lpae" }, { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "linux-tools-4.8.0-39-lowlatency" }, { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "md-modules-4.8.0-39-generic-di" }, { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "md-modules-4.8.0-39-generic-lpae-di" }, { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "message-modules-4.8.0-39-generic-di" }, { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "mouse-modules-4.8.0-39-generic-di" }, { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "mouse-modules-4.8.0-39-generic-lpae-di" }, { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "multipath-modules-4.8.0-39-generic-di" }, { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "multipath-modules-4.8.0-39-generic-lpae-di" }, { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "nfs-modules-4.8.0-39-generic-di" }, { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "nfs-modules-4.8.0-39-generic-lpae-di" }, { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "nic-modules-4.8.0-39-generic-di" }, { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "nic-modules-4.8.0-39-generic-lpae-di" }, { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "nic-pcmcia-modules-4.8.0-39-generic-di" }, { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "nic-shared-modules-4.8.0-39-generic-di" }, { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "nic-shared-modules-4.8.0-39-generic-lpae-di" }, { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "nic-usb-modules-4.8.0-39-generic-di" }, { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "nic-usb-modules-4.8.0-39-generic-lpae-di" }, { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "parport-modules-4.8.0-39-generic-di" }, { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "parport-modules-4.8.0-39-generic-lpae-di" }, { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "pata-modules-4.8.0-39-generic-di" }, { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "pcmcia-modules-4.8.0-39-generic-di" }, { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "pcmcia-storage-modules-4.8.0-39-generic-di" }, { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "plip-modules-4.8.0-39-generic-di" }, { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "plip-modules-4.8.0-39-generic-lpae-di" }, { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "ppp-modules-4.8.0-39-generic-di" }, { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "ppp-modules-4.8.0-39-generic-lpae-di" }, { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "sata-modules-4.8.0-39-generic-di" }, { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "sata-modules-4.8.0-39-generic-lpae-di" }, { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "scsi-modules-4.8.0-39-generic-di" }, { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "scsi-modules-4.8.0-39-generic-lpae-di" }, { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "serial-modules-4.8.0-39-generic-di" }, { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "storage-core-modules-4.8.0-39-generic-di" }, { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "storage-core-modules-4.8.0-39-generic-lpae-di" }, { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "usb-modules-4.8.0-39-generic-di" }, { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "usb-modules-4.8.0-39-generic-lpae-di" }, { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "virtio-modules-4.8.0-39-generic-di" }, { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "vlan-modules-4.8.0-39-generic-di" }, { "binary_version": "4.8.0-39.42~16.04.1", "binary_name": "vlan-modules-4.8.0-39-generic-lpae-di" } ] }