CVE-2018-20168

NameCVE-2018-20168
DescriptionGoogle gVisor before 2018-08-22 reuses a pagetable in a different level with the paging-structure cache intact, which allows attackers to cause a denial of service ("physical address not valid" panic) via a crafted application.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
golang-gvisor-gvisor (PTS)bookworm0.0~20221219.0-2fixed
trixie0.0~20240729.0-4fixed
forky, sid0.0~20240729.0-7fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
golang-gvisor-gvisorsource(unstable)(not affected)

Notes

- golang-gvisor-gvisor <not-affected> (Fixed before initial upload to Debian)
https://project-zero.issues.chromium.org/issues/42450740

Search for package or bug name: Reporting problems