Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2018-10853 Details

Description

A flaw was found in the way Linux kernel KVM hypervisor before 4.18 emulated instructions such as sgdt/sidt/fxsave/fxrstor. It did not check current privilege(CPL) level while emulating unprivileged instructions. An unprivileged guest user/process could use this flaw to potentially escalate privileges inside guest.

Metrics

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

URLSource(s)Tag(s)
http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00043.html CVE
https://access.redhat.com/errata/RHSA-2019:2029 CVE
https://access.redhat.com/errata/RHSA-2019:2043 CVE
https://access.redhat.com/errata/RHSA-2020:0036 CVE
https://access.redhat.com/errata/RHSA-2020:0103 CVE

see all 30 references

Weakness Enumeration

CWE-IDCWE NameSource
CWE-269Improper Privilege Management[email protected]
CWE-250Execution with Unnecessary Privileges[email protected]

Affected Products

ProductVersions
canonical ubuntu linux
16.04
18.04

CPE

  • cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
  • cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*

Remediation

  • No remediation found in references.
debian debian linux
8.0

CPE

  • cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
linux linux kernel
< 4.18

CPE

  • cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

13 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2018-10853
NVD Published Date:
Sep 11, 2018
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2018-10853 Details - Not Deferred