CVE-2018-10901: Linux Kernel

High severity, CVSS 7.8. EPSS: 0.5% chance of exploitation in the next 30 days.

A flaw was found in Linux kernel's KVM virtualization subsystem. The VMX code does not restore the GDT.LIMIT to the previous host value, but instead sets it to 64KB. With a corrupted GDT limit a host's userspace code has an ability to place malicious entries in the GDT, particularly to the per-cpu variables. An attacker can use this to escalate their privileges.

Affected products

  • Linux Linux Kernel: before 2.6.36 (fixed in 2.6.36)
  • Red Hat Enterprise Linux Desktop: version 6.0 only
  • Red Hat Enterprise Linux Server: version 6.0 only
  • Red Hat Enterprise Linux Server Aus: version 6.4 only; version 6.5 only; version 6.6 only
  • Red Hat Enterprise Linux Workstation: version 6.0 only

Published 2018-07-26. Last modified 2026-06-17.