Executive brief
A vulnerability in the Linux kernel's virtualization component (KVM) could allow a local user to crash the host system or access sensitive information from the kernel's memory. This issue affects systems running as virtual machine hosts on x86 hardware. An attacker could exploit this by running a specially crafted application within a guest environment to trigger a system failure or leak data.
Technical details
A use-after-free vulnerability exists in arch/x86/kvm/emulate.c in the Linux kernel through 4.9.3. The flaw is rooted in the incorrect emulation of memory access for the fxrstor, fxsave, sgdt, and sidt instructions. A local attacker can leverage a crafted application to trigger this use-after-free, potentially resulting in a kernel memory leak (information disclosure) or a denial of service (system crash). In some development versions, this could also lead to an exploitable kernel memory write. The fix involves introducing segmented_write_std to ensure standard read/write operations are used instead of vulnerable emulated ones.
Affected products
- Linux Linux Kernel up to 4.9.3
Timeline
- 2017-01-11: patched: Initial patch authored by Google engineers
- 2017-01-15: disclosed: NVD publication date
References
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=129a72a0d3c8e139a04512325384fe5ac119e74d
- http://www.debian.org/security/2017/dsa-3791
- http://www.openwall.com/lists/oss-security/2017/01/13/7
- http://www.securityfocus.com/bid/95430
- http://www.securitytracker.com/id/1037603
- https://bugzilla.redhat.com/show_bug.cgi?id=1413001
- https://github.com/torvalds/linux/commit/129a72a0d3c8e139a04512325384fe5ac119e74d