ZeroHour

CVE-2020-2732

CVSS 3.1
6.8 medium
EPSS
<1%p58
Published
()
Modified
Description

A flaw was discovered in the way that the KVM hypervisor handled instruction emulation for an L2 guest when nested virtualisation is enabled. Under some circumstances, an L2 guest may trick the L0 guest into accessing sensitive L1 resources that should be inaccessible to the L2 guest.

Vendors
redhat
Products
enterprise linux
Weakness
CWE-200
Vector
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.