CVE-2018-20168

MEDIUM

gVisor < 2018-08-22 - Denial of Service via Pagetable Reuse

Title source: llm
STIX 2.1

Description

Google gVisor before 2018-08-22 reuses a pagetable in a different level with the paging-structure cache intact, which allows attackers to cause a denial of service ("physical address not valid" panic) via a crafted application.

References (1)

Core 1
Core References
Patch, Vendor Advisory x_refsource_misc
https://bugs.chromium.org/p/project-zero/issues/detail?id=1674

Scores

CVSS v3 5.5
EPSS 0.0028
EPSS Percentile 19.7%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Details

CWE
CWE-20
Status published
Products (1)
google/gvisor < 2018-08-22
Published Dec 17, 2018
Tracked Since Feb 18, 2026