CVE-2017-12188

CVSS v3.1 7.8 (High)
78% Progress
CVSS v2.0 6.9 (Medium)
69% Progress
EPSS 0.06 % (28th)
0.06% Progress
Affected Products 1
Advisories 8

arch/x86/kvm/mmu.c in the Linux kernel through 4.13.5, when nested virtualisation is used, does not properly traverse guest pagetable entries to resolve a guest virtual address, which allows L1 guest OS users to execute arbitrary code on the host OS or cause a denial of service (incorrect index during page walking, and host OS crash), aka an "MMU potential stack buffer overrun."

Weaknesses
CWE-121
Stack-based Buffer Overflow
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE Status
PUBLISHED
CNA
Red Hat, Inc.
Published Date
2017-10-11 15:29:00
(7 years ago)
Updated Date
2024-04-02 18:05:18
(5 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Linux Kernel from 4.6 version and prior 4.9.57 version cpe:2.3:o:linux:linux_kernel >= 4.6 < 4.9.57
  Linux Kernel from 4.10 version and prior 4.13.8 version cpe:2.3:o:linux:linux_kernel >= 4.10 < 4.13.8
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...