CVE-2017-12188
arch/x86/kvm/mmu.c in the Linux kernel through 4.13.5, when nested virtualisation is used, does not properly traverse guest pagetable entries to resolve a guest virtual address, which allows L1 guest OS users to execute arbitrary code on the host OS or…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.44%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
arch/x86/kvm/mmu.c in the Linux kernel through 4.13.5, when nested virtualisation is used, does not properly traverse guest pagetable entries to resolve a guest virtual address, which allows L1 guest OS users to execute arbitrary code on the host OS or cause a denial of service (incorrect index during page walking, and host OS crash), aka an "MMU potential stack buffer overrun."
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
- EPSS
- 0.44% probability · 37th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-121, CWE-22
- Affected
- linux/linux kernel
- Source
- secalert@redhat.com
References
- http://www.securityfocus.com/bid/101267Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2018:0395Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:0412Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1500380Issue Tracking, Patch, Third Party Advisory
- https://patchwork.kernel.org/patch/9996579/Issue Tracking, Patch, Vendor Advisory
- https://patchwork.kernel.org/patch/9996587/Issue Tracking, Patch, Vendor Advisory
- http://www.securityfocus.com/bid/101267Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2018:0395Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:0412Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1500380Issue Tracking, Patch, Third Party Advisory
- https://patchwork.kernel.org/patch/9996579/Issue Tracking, Patch, Vendor Advisory
- https://patchwork.kernel.org/patch/9996587/Issue Tracking, Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.