A flaw was found in KVM. When updating a guest's page table entry, vm_pgoff was improperly used as the offset to get the page's pfn. As vaddr and vm_pgoff are controllable by user-mode processes, this flaw allows unprivileged local users on the host to write outside the userspace region and potentially corrupt the kernel, resulting in a denial of service condition.
| Product | Vendor | Version |
|---|---|---|
| kernel | n/a | < c884a0b27b4586e607431d86a1aa0bb4fb39169c |