Google gVisor before 2018-08-22 reuses a pagetable in a different level with the paging-structure cache intact, which allows attackers to cause a denial of service ("physical address not valid" panic) via a crafted application.
References
Link | Resource |
---|---|
https://bugs.chromium.org/p/project-zero/issues/detail?id=1674 | Patch Vendor Advisory |
Configurations
History
No history.
Information
Published : 2018-12-17 05:29
Updated : 2024-02-04 20:03
NVD link : CVE-2018-20168
Mitre link : CVE-2018-20168
CVE.ORG link : CVE-2018-20168
JSON object : View
Products Affected
- gvisor
CWE
CWE-20
Improper Input Validation