DescriptionA flaw was found in Linux kernel's KVM virtualization subsystem. The VMX code does not restore the GDT.LIMIT to the previous host value, but instead sets it to 64KB. With a corrupted GDT limit a host's userspace code has an ability to place malicious entries in the GDT, particularly to the per-cpu variables. An attacker can use this to escalate their privileges.
linux (PTS)jessie3.16.56-1+deb8u1fixed
jessie (security)3.16.68-2fixed
stretch (security)4.9.168-1+deb9u3fixed
buster, sid4.19.37-5fixed

linuxsource(unstable)(not affected)


- linux <not-affected> (Fixed before src:linux-2.6 -> src:linux rename) (2.6.36-rc1)

