CVE-2017-12154
Summary
| CVE | CVE-2017-12154 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-09-26 05:29:00 UTC |
| Updated | 2023-02-12 23:27:00 UTC |
| Description | The prepare_vmcs02 function in arch/x86/kvm/vmx.c in the Linux kernel through 4.13.3 does not ensure that the "CR8-load exiting" and "CR8-store exiting" L0 vmcs02 controls exist in cases where L1 omits the "use TPR shadow" vmcs12 control, which allows KVM L2 guest OS users to obtain read and write access to the hardware CR8 register. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Linux | Linux Kernel | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| USN-3698-1: Linux kernel vulnerabilities | Ubuntu security notices | UBUNTU | usn.ubuntu.com | |
| kvm: nVMX: Don't allow L2 to access the hardware CR8 · torvalds/linux@51aa68e · GitHub | CONFIRM | github.com | Issue Tracking, Patch, Third Party Advisory |
| [PATCH] kvm: nVMX: Don't allow L2 to access the hardware CR8 — Linux KVM | CONFIRM | www.spinics.net | Mailing List, Patch, Third Party Advisory |
| Red Hat Customer Portal | REDHAT | access.redhat.com | |
| USN-3698-2: Linux kernel (Trusty HWE) vulnerabilities | Ubuntu security notices | UBUNTU | usn.ubuntu.com | |
| Red Hat Customer Portal | REDHAT | access.redhat.com | |
| CVE-2017-12154 - Red Hat Customer Portal | MISC | access.redhat.com | |
| Linux Kernel CVE-2017-12154 Denial of Service Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Bug 1491224 – CVE-2017-12154 Kernel: kvm: nVMX: L2 guest could access hardware(L0) CR8 register | CONFIRM | bugzilla.redhat.com | Issue Tracking, Patch, Third Party Advisory |
| Red Hat Customer Portal | REDHAT | access.redhat.com | |
| Debian -- Security Information -- DSA-3981-1 linux | DEBIAN | www.debian.org | |
| kernel/git/torvalds/linux.git - Linux kernel source tree | CONFIRM | git.kernel.org | Issue Tracking, Patch, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.