ZeroHour

CVE-2018-12904

PoC ×2
CVSS 3.0
4.9 medium
EPSS
1%p66
Published
()
Modified
Description

In arch/x86/kvm/vmx.c in the Linux kernel before 4.17.2, when nested virtualization is used, local attackers could cause L1 KVM guests to VMEXIT, potentially allowing privilege escalations and denial of service attacks due to lack of checking of CPL.

Vendors
linuxcanonical
Products
linux kernel, ubuntu linux
Vector
CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L

In the news

No ingested article mentions this CVE yet.