The KVM implementation in the Linux kernel through 4.14.7 allows attackers to obtain potentially sensitive information from kernel memory, aka a write_mmio stack-based out-of-bounds read, related to arch/x86/kvm/x86.c and include/trace/events/kvm.h.
| Software | From | Fixed in |
|---|---|---|
| linux / linux_kernel | - | 4.14.7.x |
| debian / debian_linux | 9.0 | 9.0.x |