A flaw was found in Linux kernel's KVM virtualization subsystem. The VMX code does not restore the GDT.LIMIT to the previous host value, but instead sets it to 64KB. With a corrupted GDT limit a host's userspace code has an ability to place malicious entries in the GDT, particularly to the per-cpu variables. An attacker can use this to escalate their privileges.
{
"binaries": [
{
"binary_version": "5.0.0-1012.12~18.04.2",
"binary_name": "linux-azure-edge-cloud-tools-5.0.0-1012"
},
{
"binary_version": "5.0.0-1012.12~18.04.2",
"binary_name": "linux-azure-edge-tools-5.0.0-1012"
},
{
"binary_version": "5.0.0-1012.12~18.04.2",
"binary_name": "linux-azure-headers-5.0.0-1012"
},
{
"binary_version": "5.0.0-1012.12~18.04.2",
"binary_name": "linux-buildinfo-5.0.0-1012-azure"
},
{
"binary_version": "5.0.0-1012.12~18.04.2",
"binary_name": "linux-cloud-tools-5.0.0-1012-azure"
},
{
"binary_version": "5.0.0-1012.12~18.04.2",
"binary_name": "linux-headers-5.0.0-1012-azure"
},
{
"binary_version": "5.0.0-1012.12~18.04.2",
"binary_name": "linux-image-unsigned-5.0.0-1012-azure"
},
{
"binary_version": "5.0.0-1012.12~18.04.2",
"binary_name": "linux-modules-5.0.0-1012-azure"
},
{
"binary_version": "5.0.0-1012.12~18.04.2",
"binary_name": "linux-modules-extra-5.0.0-1012-azure"
},
{
"binary_version": "5.0.0-1012.12~18.04.2",
"binary_name": "linux-tools-5.0.0-1012-azure"
}
]
}