Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:19164
HistoryMay 16, 2019 - 2:50 a.m.

Authorization Bypass

2019-05-1602:50:21
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
16

EPSS

0.001

Percentile

25.3%

Linux kernel is vulnerable to authorization bypass attacks. This is due to disabled external interrupts in Linux kernel built with the KVM visualization support (CONFIG_KVM), with nested visualization (nVMX) feature enabled (nested=1). A local guest attacker could obtain read and write access to the hardware CR8 register causing an application crash.

References