{"api_version":"1","generated_at":"2026-07-23T15:41:53+00:00","cve":"CVE-2018-18021","urls":{"html":"https://cve.report/CVE-2018-18021","api":"https://cve.report/api/cve/CVE-2018-18021.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2018-18021","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2018-18021"},"summary":{"title":"CVE-2018-18021","description":"arch/arm64/kvm/guest.c in KVM in the Linux kernel before 4.18.12 on the arm64 platform mishandles the KVM_SET_ON_REG ioctl. This is exploitable by attackers who can create virtual machines. An attacker can arbitrarily redirect the hypervisor flow of control (with full register control). An attacker can also cause a denial of service (hypervisor panic) via an illegal exception return. This occurs because of insufficient restrictions on userspace access to the core register file, and because PSTATE.M validation does not prevent unintended execution modes.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2018-10-07 06:29:00","updated_at":"2019-04-03 01:29:00"},"problem_types":["CWE-20"],"metrics":[],"references":[{"url":"https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.18.12","name":"https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.18.12","refsource":"MISC","tags":["Patch"],"title":"","mime":"text/plain","httpstatus":"200","archivestatus":"200"},{"url":"https://www.debian.org/security/2018/dsa-4313","name":"DSA-4313","refsource":"DEBIAN","tags":["Third Party Advisory"],"title":"Debian -- Security Information -- DSA-4313-1 linux","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.openwall.com/lists/oss-security/2018/10/02/2","name":"https://www.openwall.com/lists/oss-security/2018/10/02/2","refsource":"MISC","tags":["Mailing List","Patch","Third Party Advisory"],"title":"oss-security - arm64 Linux kernel: Privilege escalation by taking control of the\n KVM hypervisor","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/torvalds/linux/commit/2a3f93459d689d990b3ecfbe782fec89b97d3279","name":"https://github.com/torvalds/linux/commit/2a3f93459d689d990b3ecfbe782fec89b97d3279","refsource":"MISC","tags":["Patch"],"title":"arm64: KVM: Sanitize PSTATE.M when being set from userspace · torvalds/linux@2a3f934 · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=2a3f93459d689d990b3ecfbe782fec89b97d3279","name":"http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=2a3f93459d689d990b3ecfbe782fec89b97d3279","refsource":"MISC","tags":["Patch"],"title":"kernel/git/torvalds/linux.git - Linux kernel source tree","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://usn.ubuntu.com/3821-1/","name":"USN-3821-1","refsource":"UBUNTU","tags":["Third Party Advisory"],"title":"USN-3821-1: Linux kernel vulnerabilities | Ubuntu security notices | Ubuntu","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://usn.ubuntu.com/3931-1/","name":"USN-3931-1","refsource":"UBUNTU","tags":[],"title":"USN-3931-1: Linux kernel vulnerabilities | Ubuntu security notices","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://usn.ubuntu.com/3931-2/","name":"USN-3931-2","refsource":"UBUNTU","tags":[],"title":"USN-3931-2: Linux kernel (HWE) vulnerabilities | Ubuntu security notices","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/torvalds/linux/commit/d26c25a9d19b5976b319af528886f89cf455692d","name":"https://github.com/torvalds/linux/commit/d26c25a9d19b5976b319af528886f89cf455692d","refsource":"MISC","tags":["Patch"],"title":"arm64: KVM: Tighten guest core register access from userspace · torvalds/linux@d26c25a · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://usn.ubuntu.com/3821-2/","name":"USN-3821-2","refsource":"UBUNTU","tags":["Third Party Advisory"],"title":"USN-3821-2: Linux kernel (Xenial HWE) vulnerabilities | Ubuntu security notices | Ubuntu","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/105550","name":"105550","refsource":"BID","tags":["Third Party Advisory","VDB Entry"],"title":"Linux Kernel 'arch/arm64/kvm/guest.c' Local Privilege Escalation Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://access.redhat.com/errata/RHSA-2018:3656","name":"RHSA-2018:3656","refsource":"REDHAT","tags":["Third Party Advisory"],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=d26c25a9d19b5976b319af528886f89cf455692d","name":"http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=d26c25a9d19b5976b319af528886f89cf455692d","refsource":"MISC","tags":["Patch"],"title":"kernel/git/torvalds/linux.git - Linux kernel source tree","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2018-18021","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2018-18021","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2018","cve_id":"18021","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"canonical","cpe5":"ubuntu_linux","cpe6":"14.04","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"lts","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"18021","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"canonical","cpe5":"ubuntu_linux","cpe6":"16.04","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"lts","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"18021","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"canonical","cpe5":"ubuntu_linux","cpe6":"14.04","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"lts","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"18021","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"canonical","cpe5":"ubuntu_linux","cpe6":"16.04","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"lts","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"18021","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"debian","cpe5":"debian_linux","cpe6":"9.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"18021","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"debian","cpe5":"debian_linux","cpe6":"9.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"18021","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"linux","cpe5":"linux_kernel","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"18021","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"linux","cpe5":"linux_kernel","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2018-18021","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"arch/arm64/kvm/guest.c in KVM in the Linux kernel before 4.18.12 on the arm64 platform mishandles the KVM_SET_ON_REG ioctl. This is exploitable by attackers who can create virtual machines. An attacker can arbitrarily redirect the hypervisor flow of control (with full register control). An attacker can also cause a denial of service (hypervisor panic) via an illegal exception return. This occurs because of insufficient restrictions on userspace access to the core register file, and because PSTATE.M validation does not prevent unintended execution modes."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"USN-3821-1","refsource":"UBUNTU","url":"https://usn.ubuntu.com/3821-1/"},{"name":"https://github.com/torvalds/linux/commit/2a3f93459d689d990b3ecfbe782fec89b97d3279","refsource":"MISC","url":"https://github.com/torvalds/linux/commit/2a3f93459d689d990b3ecfbe782fec89b97d3279"},{"name":"https://www.openwall.com/lists/oss-security/2018/10/02/2","refsource":"MISC","url":"https://www.openwall.com/lists/oss-security/2018/10/02/2"},{"name":"https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.18.12","refsource":"MISC","url":"https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.18.12"},{"name":"RHSA-2018:3656","refsource":"REDHAT","url":"https://access.redhat.com/errata/RHSA-2018:3656"},{"name":"https://github.com/torvalds/linux/commit/d26c25a9d19b5976b319af528886f89cf455692d","refsource":"MISC","url":"https://github.com/torvalds/linux/commit/d26c25a9d19b5976b319af528886f89cf455692d"},{"name":"105550","refsource":"BID","url":"http://www.securityfocus.com/bid/105550"},{"name":"USN-3821-2","refsource":"UBUNTU","url":"https://usn.ubuntu.com/3821-2/"},{"name":"http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=2a3f93459d689d990b3ecfbe782fec89b97d3279","refsource":"MISC","url":"http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=2a3f93459d689d990b3ecfbe782fec89b97d3279"},{"name":"http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=d26c25a9d19b5976b319af528886f89cf455692d","refsource":"MISC","url":"http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=d26c25a9d19b5976b319af528886f89cf455692d"},{"name":"DSA-4313","refsource":"DEBIAN","url":"https://www.debian.org/security/2018/dsa-4313"},{"refsource":"UBUNTU","name":"USN-3931-1","url":"https://usn.ubuntu.com/3931-1/"},{"refsource":"UBUNTU","name":"USN-3931-2","url":"https://usn.ubuntu.com/3931-2/"}]}},"nvd":{"publishedDate":"2018-10-07 06:29:00","lastModifiedDate":"2019-04-03 01:29:00","problem_types":["CWE-20"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.1,"baseSeverity":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.2},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:N/I:P/A:P","accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":3.6},"severity":"LOW","exploitabilityScore":3.9,"impactScore":4.9,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"4.18.12","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2018","CveId":"18021","Ordinal":"134844","Title":"CVE-2018-18021","CVE":"CVE-2018-18021","Year":"2018"},"notes":[{"CveYear":"2018","CveId":"18021","Ordinal":"1","NoteData":"arch/arm64/kvm/guest.c in KVM in the Linux kernel before 4.18.12 on the arm64 platform mishandles the KVM_SET_ON_REG ioctl. This is exploitable by attackers who can create virtual machines. An attacker can arbitrarily redirect the hypervisor flow of control (with full register control). An attacker can also cause a denial of service (hypervisor panic) via an illegal exception return. This occurs because of insufficient restrictions on userspace access to the core register file, and because PSTATE.M validation does not prevent unintended execution modes.","Type":"Description","Title":null},{"CveYear":"2018","CveId":"18021","Ordinal":"2","NoteData":"2018-10-07","Type":"Other","Title":"Published"},{"CveYear":"2018","CveId":"18021","Ordinal":"3","NoteData":"2019-04-02","Type":"Other","Title":"Modified"}]}}}