CVE-2018-16882: Canonical Ubuntu Linux
High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.
A use-after-free issue was found in the way the Linux kernel's KVM hypervisor processed posted interrupts when nested(=1) virtualization is enabled. In nested_get_vmcs12_pages(), in case of an error while processing posted interrupt address, it unmaps the 'pi_desc_page' without resetting 'pi_desc' descriptor address, which is later used in pi_test_and_clear_on(). A guest user/process could use this flaw to crash the host kernel resulting in DoS or potentially gain privileged access to a system. Kernel versions before 4.14.91 and before 4.19.13 are vulnerable.
Affected products
- Canonical Ubuntu Linux: version 14.04 only; version 16.04 only; version 18.04 only; version 18.10 only
- Linux Linux Kernel: from 4.14, before 4.14.91 (fixed in 4.14.91); from 4.15, before 4.19.13 (fixed in 4.19.13)
Published 2019-01-03. Last modified 2026-06-17.