Lucene search

K
redhatcveRedhat.comRH:CVE-2020-12888
HistoryMay 15, 2020 - 6:25 p.m.

CVE-2020-12888

2020-05-1518:25:34
redhat.com
access.redhat.com
26

0.0005 Low

EPSS

Percentile

17.3%

A flaw was found in the Linux kernel, where it allows userspace processes, for example, a guest VM, to directly access h/w devices via its VFIO driver modules. The VFIO modules allow users to enable or disable access to the devices’ MMIO memory address spaces. If a user attempts to access the read/write devices’ MMIO address space when it is disabled, some h/w devices issue an interrupt to the CPU to indicate a fatal error condition, crashing the system. This flaw allows a guest user or process to crash the host system resulting in a denial of service.