The load_segment_descriptor implementation in arch/x86/kvm/emulate.c in the Linux kernel before 4.9.5 improperly emulates a "MOV SS, NULL selector" instruction, which allows guest OS users to cause a denial of service (guest OS crash) or gain guest OS privileges via a crafted application.
Product | Vendor | Version |
---|---|---|
n/a | n/a | c9387dfa08afff4cd1f875331c6eb24ac6758d608976603c7398c039dde35890 |