CVE-2018-20168
MEDIUMgVisor < 2018-08-22 - Denial of Service via Pagetable Reuse
Title source: llmDescription
Google gVisor before 2018-08-22 reuses a pagetable in a different level with the paging-structure cache intact, which allows attackers to cause a denial of service ("physical address not valid" panic) via a crafted application.
References (1)
Core 1
Core References
Patch, Vendor Advisory x_refsource_misc
https://bugs.chromium.org/p/project-zero/issues/detail?id=1674
Scores
CVSS v3
5.5
EPSS
0.0028
EPSS Percentile
19.7%
Attack Vector
LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Details
CWE
CWE-20
Status
published
Products (1)
google/gvisor
< 2018-08-22
Published
Dec 17, 2018
Tracked Since
Feb 18, 2026