CVE-2018-12207
Vulnerability Summary
Timeline
Description
Improper invalidation for page table updates by a virtual guest operating system for multiple Intel(R) Processors may allow an authenticated user to potentially enable denial of service of the host system via local access.
CVSS Metrics
- v3.1•MEDIUM•Score: 6.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
- v2.0•MEDIUM•Score: 4.9AV:L/AC:L/Au:N/C:N/I:N/A:C
EPSS Trends
Current EPSS score: 0.92%• Percentile: 59%
Techniques & Countermeasures
- CWE-20•Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Affected Systems
- canonical•ubuntu_linux
14.04
- debian•linux
< 5.3.9-2 | < 5.3.9-2 | < 5.3.9-2 | < 5.3.9-2
- debian•xen
< 4.11.3+24-g14b62ab3e5-1 | < 4.11.3+24-g14b62ab3e5-1 | < 4.11.3+24-g14b62ab3e5-1 | < 4.11.3+24-g14b62ab3e5-1
- ubuntu•linux
all | < 4.4.0-168.197 | < 4.15.0-69.78
- ubuntu•linux-aws
< 4.4.0-1058.62 | < 4.4.0-1098.109 | < 4.15.0-1054.56
- ubuntu•linux-aws-fips
< 4.15.0-2018.18 | all
- ubuntu•linux-aws-hwe
< 4.15.0-1054.56~16.04.1
- ubuntu•linux-azure
< 4.15.0-1063.68~14.04.1 | < 4.15.0-1063.68 | < 5.0.0-1025.27~18.04.1
- ubuntu•linux-azure-edge
all
- ubuntu•linux-azure-fde-5.15
< 5.15.0-1114.123~20.04.1
- ubuntu•linux-azure-fips
< 4.15.0-2006.7 | all
- ubuntu•linux-bluefield
all
- ubuntu•linux-fips
< 4.4.0-1025.30 | all
- ubuntu•linux-gcp
< 4.15.0-1049.52 | < 5.0.0-1025.26~18.04.1
- ubuntu•linux-gcp-edge
all
- ubuntu•linux-gcp-fips
all
- ubuntu•linux-gke-4.15
< 4.15.0-1048.51
- ubuntu•linux-gke-5.0
< 5.0.0-1025.26~18.04.1
- ubuntu•linux-hwe
< 4.15.0-69.78~16.04.1 | < 5.0.0-35.38~18.04.1
- ubuntu•linux-hwe-edge
all | all
- ubuntu•linux-intel-iot-realtime
all
- ubuntu•linux-kvm
< 4.4.0-1062.69 | < 4.15.0-1050.50
- ubuntu•linux-lts-xenial
< 4.4.0-168.197~14.04.1
- ubuntu•linux-oem
< 4.15.0-1063.72
- ubuntu•linux-oem-osp1
< 5.0.0-1027.31
- ubuntu•linux-oracle
< 4.15.0-1029.32~16.04.1 | < 4.15.0-1029.32
- ubuntu•linux-raspi-realtime
all
- ubuntu•linux-raspi2
< 4.4.0-1126.135 | < 4.15.0-1052.56 | all
- ubuntu•linux-realtime
all
- ubuntu•linux-snapdragon
< 4.4.0-1130.138 | < 4.15.0-1069.76
- ubuntu•xen
all | all
- debian•debian_linux
9.0
- f5•big-ip_access_policy_manager
≥ 11.5.2, ≤ 11.6.5 | ≥ 12.1.0, ≤ 12.1.5 | ≥ 13.1.0, ≤ 13.1.3 | ≥ 14.1.0, ≤ 14.1.2 | ≥ 15.0.0, ≤ 15.0.1
- f5•big-ip_advanced_firewall_manager
≥ 11.5.2, ≤ 11.6.5 | ≥ 12.1.0, ≤ 12.1.5 | ≥ 13.1.0, ≤ 13.1.3 | ≥ 14.1.0, ≤ 14.1.2 | ≥ 15.0.0, ≤ 15.0.1
- f5•big-ip_analytics
≥ 11.5.2, ≤ 11.6.5 | ≥ 12.1.0, ≤ 12.1.5 | ≥ 13.1.0, ≤ 13.1.3 | ≥ 14.1.0, ≤ 14.1.2 | ≥ 15.0.0, ≤ 15.0.1
- f5•big-ip_application_acceleration_manager
≥ 11.5.2, ≤ 11.6.5 | ≥ 12.1.0, ≤ 12.1.5 | ≥ 13.1.0, ≤ 13.1.3 | ≥ 14.1.0, ≤ 14.1.2 | ≥ 15.0.0, ≤ 15.0.1
- f5•big-ip_application_security_manager
≥ 11.5.2, ≤ 11.6.5 | ≥ 12.1.0, ≤ 12.1.5 | ≥ 13.1.0, ≤ 13.1.3 | ≥ 14.1.0, ≤ 14.1.2 | ≥ 15.0.0, ≤ 15.0.1
- f5•big-ip_domain_name_system
≥ 11.5.2, ≤ 11.6.5 | ≥ 12.1.0, ≤ 12.1.5 | ≥ 13.1.0, ≤ 13.1.3 | ≥ 14.1.0, ≤ 14.1.2 | ≥ 15.0.0, ≤ 15.0.1
- f5•big-ip_fraud_protection_service
≥ 11.5.2, ≤ 11.6.5 | ≥ 12.1.0, ≤ 12.1.5 | ≥ 13.1.0, ≤ 13.1.3 | ≥ 14.1.0, ≤ 14.1.2 | ≥ 15.0.0, ≤ 15.0.1
- f5•big-ip_global_traffic_manager
≥ 11.5.2, ≤ 11.6.5 | ≥ 12.1.0, ≤ 12.1.5 | ≥ 13.1.0, ≤ 13.1.3 | ≥ 14.1.0, ≤ 14.1.2 | ≥ 15.0.0, ≤ 15.0.1
- f5•big-ip_link_controller
≥ 11.5.2, ≤ 11.6.5 | ≥ 12.1.0, ≤ 12.1.5 | ≥ 13.1.0, ≤ 13.1.3 | ≥ 14.1.0, ≤ 14.1.2 | ≥ 15.0.0, ≤ 15.0.1
- f5•big-ip_local_traffic_manager
≥ 11.5.2, ≤ 11.6.5 | ≥ 12.1.0, ≤ 12.1.5 | ≥ 13.1.0, ≤ 13.1.3 | ≥ 14.1.0, ≤ 14.1.2 | ≥ 15.0.0, ≤ 15.0.1
- f5•big-ip_policy_enforcement_manager
≥ 11.5.2, ≤ 11.6.5 | ≥ 12.1.0, ≤ 12.1.5 | ≥ 13.1.0, ≤ 13.1.3 | ≥ 14.1.0, ≤ 14.1.2 | ≥ 15.0.0, ≤ 15.0.1
- f5•big-iq_centralized_management
≥ 5.2.0, ≤ 5.4.0 | ≥ 6.0.0, ≤ 6.1.0 | 7.0.0
- f5•enterprise_manager
3.1.1
- fedoraproject•fedora
30 | 31
- intel•celeron_g1610_firmware
na
- intel•celeron_g1610t_firmware
na
- intel•celeron_g1620_firmware
na
- intel•celeron_g1620t_firmware
na
Showing first 50 affected entries in server-rendered view.
References (28)
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/I5WWPW4BSZDDW7VHU427XTVXV7ROOFFW/
- https://access.redhat.com/errata/RHSA-2019:3916
- https://access.redhat.com/errata/RHSA-2019:3936
- https://access.redhat.com/errata/RHSA-2019:3941
- https://usn.ubuntu.com/4186-2/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IZYATWNUGHRBG6I3TC24YHP5Y3J7I6KH/
- http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00042.html
- https://access.redhat.com/errata/RHSA-2020:0026
- https://access.redhat.com/errata/RHSA-2020:0028
- https://www.debian.org/security/2020/dsa-4602
- https://seclists.org/bugtraq/2020/Jan/21
- https://access.redhat.com/errata/RHSA-2020:0204
- https://security.gentoo.org/glsa/202003-56
- https://www.oracle.com/security-alerts/cpujul2020.html
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00210.html
- https://support.f5.com/csp/article/K17269881?utm_source=f5support&%3Butm_medium=RSS
- https://ubuntu.com/security/CVE-2018-12207
- https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/TAA_MCEPSC_i915
- https://software.intel.com/security-software-guidance/api-app/insights/deep-dive-machine-check-error-avoidance-page-size-change
- https://xenbits.xen.org/xsa/advisory-304.html
- https://ubuntu.com/security/notices/USN-4183-1
- https://ubuntu.com/security/notices/USN-4184-1
- https://ubuntu.com/security/notices/USN-4185-1
- https://ubuntu.com/security/notices/USN-4185-2
- https://ubuntu.com/security/notices/USN-4186-1
- https://ubuntu.com/security/notices/USN-4186-2
- https://www.cve.org/CVERecord?id=CVE-2018-12207
- https://security-tracker.debian.org/tracker/CVE-2018-12207