{"api_version":"1","generated_at":"2026-07-24T21:51:27+00:00","cve":"CVE-2017-12154","urls":{"html":"https://cve.report/CVE-2017-12154","api":"https://cve.report/api/cve/CVE-2017-12154.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-12154","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-12154"},"summary":{"title":"CVE-2017-12154","description":"The prepare_vmcs02 function in arch/x86/kvm/vmx.c in the Linux kernel through 4.13.3 does not ensure that the \"CR8-load exiting\" and \"CR8-store exiting\" L0 vmcs02 controls exist in cases where L1 omits the \"use TPR shadow\" vmcs12 control, which allows KVM L2 guest OS users to obtain read and write access to the hardware CR8 register.","state":"PUBLIC","assigner":"secalert@redhat.com","published_at":"2017-09-26 05:29:00","updated_at":"2023-02-12 23:27:00"},"problem_types":["NVD-CWE-noinfo"],"metrics":[],"references":[{"url":"https://usn.ubuntu.com/3698-1/","name":"USN-3698-1","refsource":"UBUNTU","tags":[],"title":"USN-3698-1: Linux kernel vulnerabilities | Ubuntu security notices","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/torvalds/linux/commit/51aa68e7d57e3217192d88ce90fd5b8ef29ec94f","name":"https://github.com/torvalds/linux/commit/51aa68e7d57e3217192d88ce90fd5b8ef29ec94f","refsource":"CONFIRM","tags":["Issue Tracking","Patch","Third Party Advisory"],"title":"kvm: nVMX: Don't allow L2 to access the hardware CR8 · torvalds/linux@51aa68e · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.spinics.net/lists/kvm/msg155414.html","name":"https://www.spinics.net/lists/kvm/msg155414.html","refsource":"CONFIRM","tags":["Mailing List","Patch","Third Party Advisory"],"title":"[PATCH] kvm: nVMX: Don't allow L2 to access the hardware CR8 — Linux KVM","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://access.redhat.com/errata/RHSA-2019:1946","name":"RHSA-2019:1946","refsource":"REDHAT","tags":[],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://usn.ubuntu.com/3698-2/","name":"USN-3698-2","refsource":"UBUNTU","tags":[],"title":"USN-3698-2: Linux kernel (Trusty HWE) vulnerabilities | Ubuntu security notices","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://access.redhat.com/errata/RHSA-2018:0676","name":"RHSA-2018:0676","refsource":"REDHAT","tags":[],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://access.redhat.com/security/cve/CVE-2017-12154","name":"https://access.redhat.com/security/cve/CVE-2017-12154","refsource":"MISC","tags":[],"title":"CVE-2017-12154 - Red Hat Customer Portal","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/100856","name":"100856","refsource":"BID","tags":["Third Party Advisory","VDB Entry"],"title":"Linux Kernel CVE-2017-12154 Denial of Service Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1491224","name":"https://bugzilla.redhat.com/show_bug.cgi?id=1491224","refsource":"CONFIRM","tags":["Issue Tracking","Patch","Third Party Advisory"],"title":"Bug 1491224 – CVE-2017-12154 Kernel: kvm: nVMX: L2 guest could access hardware(L0) CR8 register","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://access.redhat.com/errata/RHSA-2018:1062","name":"RHSA-2018:1062","refsource":"REDHAT","tags":[],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.debian.org/security/2017/dsa-3981","name":"DSA-3981","refsource":"DEBIAN","tags":[],"title":"Debian -- Security Information -- DSA-3981-1 linux","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=51aa68e7d57e3217192d88ce90fd5b8ef29ec94f","name":"http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=51aa68e7d57e3217192d88ce90fd5b8ef29ec94f","refsource":"CONFIRM","tags":["Issue Tracking","Patch","Third Party Advisory"],"title":"kernel/git/torvalds/linux.git - Linux kernel source tree","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-12154","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-12154","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"12154","vulnerable":"1","versionEndIncluding":"4.13.3","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"linux","cpe5":"linux_kernel","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_version":"4.0","data_type":"CVE","data_format":"MITRE","CVE_data_meta":{"ID":"CVE-2017-12154","ASSIGNER":"secalert@redhat.com","STATE":"PUBLIC"},"description":{"description_data":[{"lang":"eng","value":"The prepare_vmcs02 function in arch/x86/kvm/vmx.c in the Linux kernel through 4.13.3 does not ensure that the \"CR8-load exiting\" and \"CR8-store exiting\" L0 vmcs02 controls exist in cases where L1 omits the \"use TPR shadow\" vmcs12 control, which allows KVM L2 guest OS users to obtain read and write access to the hardware CR8 register."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"incorrect access control"}]}]},"affects":{"vendor":{"vendor_data":[{"vendor_name":"n/a","product":{"product_data":[{"product_name":"Linux kernel through 4.13.3","version":{"version_data":[{"version_affected":"=","version_value":"Linux kernel through 4.13.3"}]}}]}}]}},"references":{"reference_data":[{"url":"http://www.debian.org/security/2017/dsa-3981","refsource":"MISC","name":"http://www.debian.org/security/2017/dsa-3981"},{"url":"https://access.redhat.com/errata/RHSA-2018:0676","refsource":"MISC","name":"https://access.redhat.com/errata/RHSA-2018:0676"},{"url":"https://access.redhat.com/errata/RHSA-2018:1062","refsource":"MISC","name":"https://access.redhat.com/errata/RHSA-2018:1062"},{"url":"https://access.redhat.com/errata/RHSA-2019:1946","refsource":"MISC","name":"https://access.redhat.com/errata/RHSA-2019:1946"},{"url":"http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=51aa68e7d57e3217192d88ce90fd5b8ef29ec94f","refsource":"MISC","name":"http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=51aa68e7d57e3217192d88ce90fd5b8ef29ec94f"},{"url":"http://www.securityfocus.com/bid/100856","refsource":"MISC","name":"http://www.securityfocus.com/bid/100856"},{"url":"https://github.com/torvalds/linux/commit/51aa68e7d57e3217192d88ce90fd5b8ef29ec94f","refsource":"MISC","name":"https://github.com/torvalds/linux/commit/51aa68e7d57e3217192d88ce90fd5b8ef29ec94f"},{"url":"https://usn.ubuntu.com/3698-1/","refsource":"MISC","name":"https://usn.ubuntu.com/3698-1/"},{"url":"https://usn.ubuntu.com/3698-2/","refsource":"MISC","name":"https://usn.ubuntu.com/3698-2/"},{"url":"https://www.spinics.net/lists/kvm/msg155414.html","refsource":"MISC","name":"https://www.spinics.net/lists/kvm/msg155414.html"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1491224","refsource":"MISC","name":"https://bugzilla.redhat.com/show_bug.cgi?id=1491224"}]}},"nvd":{"publishedDate":"2017-09-26 05:29:00","lastModifiedDate":"2023-02-12 23:27:00","problem_types":["NVD-CWE-noinfo"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":7.1,"baseSeverity":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.2},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:P/A:N","accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":3.6},"severity":"LOW","exploitabilityScore":3.9,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndIncluding":"4.13.3","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"12154","Ordinal":"109301","Title":"CVE-2017-12154","CVE":"CVE-2017-12154","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"12154","Ordinal":"1","NoteData":"The prepare_vmcs02 function in arch/x86/kvm/vmx.c in the Linux kernel through 4.13.3 does not ensure that the \"CR8-load exiting\" and \"CR8-store exiting\" L0 vmcs02 controls exist in cases where L1 omits the \"use TPR shadow\" vmcs12 control, which allows KVM L2 guest OS users to obtain read and write access to the hardware CR8 register.","Type":"Description","Title":null},{"CveYear":"2017","CveId":"12154","Ordinal":"2","NoteData":"2017-09-26","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"12154","Ordinal":"3","NoteData":"2019-07-30","Type":"Other","Title":"Modified"}]}}}