Lucene search

K
cvelistRedhatCVELIST:CVE-2017-12154
HistorySep 26, 2017 - 5:00 a.m.

CVE-2017-12154

2017-09-2605:00:00
redhat
www.cve.org
1

7 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

25.5%

The prepare_vmcs02 function in arch/x86/kvm/vmx.c in the Linux kernel through 4.13.3 does not ensure that the “CR8-load exiting” and “CR8-store exiting” L0 vmcs02 controls exist in cases where L1 omits the “use TPR shadow” vmcs12 control, which allows KVM L2 guest OS users to obtain read and write access to the hardware CR8 register.

CNA Affected

[
  {
    "product": "Linux kernel through 4.13.3",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "Linux kernel through 4.13.3"
      }
    ]
  }
]