VulnerabilityModified
CVE-2018-12904
In arch/x86/kvm/vmx.c in the Linux kernel before 4.17.2, when nested virtualization is used, local attackers could cause L1 KVM guests to VMEXIT, potentially allowing privilege escalations and denial of service attacks due to lack of checking of CPL.
MEDIUM 4.9EPSS 1.18%
Does this matter?
Lower severity and a low EPSS score (1.18%). Track it; it rarely justifies an emergency change on its own.
Description
In arch/x86/kvm/vmx.c in the Linux kernel before 4.17.2, when nested virtualization is used, local attackers could cause L1 KVM guests to VMEXIT, potentially allowing privilege escalations and denial of service attacks due to lack of checking of CPL.
- CVSS 3.0
- 4.9 MEDIUMCVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
- EPSS
- 1.18% probability · 66th percentile
- CISA KEV
- Not listed
- Affected
- linux/linux kernel · canonical/ubuntu linux
- Source
- cve@mitre.org
References
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=727ba748e110b4de50d142edca9d6a9b7e6111d8Patch, Vendor Advisory
- https://bugs.chromium.org/p/project-zero/issues/detail?id=1589Exploit, Third Party Advisory
- https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.17.2Release Notes, Vendor Advisory
- https://github.com/torvalds/linux/commit/727ba748e110b4de50d142edca9d6a9b7e6111d8Patch, Third Party Advisory
- https://usn.ubuntu.com/3752-1/Third Party Advisory
- https://usn.ubuntu.com/3752-2/Third Party Advisory
- https://usn.ubuntu.com/3752-3/Third Party Advisory
- https://www.exploit-db.com/exploits/44944/Exploit, Third Party Advisory, VDB Entry
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=727ba748e110b4de50d142edca9d6a9b7e6111d8Patch, Vendor Advisory
- https://bugs.chromium.org/p/project-zero/issues/detail?id=1589Exploit, Third Party Advisory
- https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.17.2Release Notes, Vendor Advisory
- https://github.com/torvalds/linux/commit/727ba748e110b4de50d142edca9d6a9b7e6111d8Patch, Third Party Advisory
- https://usn.ubuntu.com/3752-1/Third Party Advisory
- https://usn.ubuntu.com/3752-2/Third Party Advisory
- https://usn.ubuntu.com/3752-3/Third Party Advisory
- https://www.exploit-db.com/exploits/44944/Exploit, Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.