{"api_version":"1","generated_at":"2026-07-23T09:36:13+00:00","cve":"CVE-2018-12904","urls":{"html":"https://cve.report/CVE-2018-12904","api":"https://cve.report/api/cve/CVE-2018-12904.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2018-12904","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2018-12904"},"summary":{"title":"CVE-2018-12904","description":"In arch/x86/kvm/vmx.c in the Linux kernel before 4.17.2, when nested virtualization is used, local attackers could cause L1 KVM guests to VMEXIT, potentially allowing privilege escalations and denial of service attacks due to lack of checking of CPL.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2018-06-27 11:29:00","updated_at":"2019-10-03 00:03:00"},"problem_types":["NVD-CWE-noinfo"],"metrics":[],"references":[{"url":"https://usn.ubuntu.com/3752-1/","name":"USN-3752-1","refsource":"UBUNTU","tags":["Third Party Advisory"],"title":"USN-3752-1: Linux kernel vulnerabilities | Ubuntu security notices | Ubuntu","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=727ba748e110b4de50d142edca9d6a9b7e6111d8","name":"http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=727ba748e110b4de50d142edca9d6a9b7e6111d8","refsource":"MISC","tags":["Patch","Vendor Advisory"],"title":"kernel/git/torvalds/linux.git - Linux kernel source tree","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://usn.ubuntu.com/3752-2/","name":"USN-3752-2","refsource":"UBUNTU","tags":["Third Party Advisory"],"title":"USN-3752-2: Linux kernel (HWE) vulnerabilities | Ubuntu security notices | Ubuntu","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.exploit-db.com/exploits/44944/","name":"44944","refsource":"EXPLOIT-DB","tags":["Exploit","Third Party Advisory","VDB Entry"],"title":"KVM (Nested Virtualization) - L1 Guest Privilege Escalation - Linux dos Exploit","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://github.com/torvalds/linux/commit/727ba748e110b4de50d142edca9d6a9b7e6111d8","name":"https://github.com/torvalds/linux/commit/727ba748e110b4de50d142edca9d6a9b7e6111d8","refsource":"MISC","tags":["Patch","Third Party Advisory"],"title":"kvm: nVMX: Enforce cpl=0 for VMX instructions · torvalds/linux@727ba74 · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.17.2","name":"https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.17.2","refsource":"MISC","tags":["Release Notes","Vendor Advisory"],"title":"","mime":"text/plain","httpstatus":"200","archivestatus":"200"},{"url":"https://bugs.chromium.org/p/project-zero/issues/detail?id=1589","name":"https://bugs.chromium.org/p/project-zero/issues/detail?id=1589","refsource":"MISC","tags":["Exploit","Third Party Advisory"],"title":"1589 - \n \n \n project-zero -\n \n \n Project Zero - \n \n Monorail","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://usn.ubuntu.com/3752-3/","name":"USN-3752-3","refsource":"UBUNTU","tags":["Third Party Advisory"],"title":"USN-3752-3: Linux kernel (Azure, GCP, OEM) vulnerabilities | Ubuntu security notices | Ubuntu","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2018-12904","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2018-12904","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2018","cve_id":"12904","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"canonical","cpe5":"ubuntu_linux","cpe6":"16.04","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"lts","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"12904","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"canonical","cpe5":"ubuntu_linux","cpe6":"18.04","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"lts","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"12904","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"canonical","cpe5":"ubuntu_linux","cpe6":"16.04","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"lts","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"12904","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"canonical","cpe5":"ubuntu_linux","cpe6":"18.04","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"lts","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"12904","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"linux","cpe5":"linux_kernel","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"12904","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"linux","cpe5":"linux_kernel","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2018-12904","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"In arch/x86/kvm/vmx.c in the Linux kernel before 4.17.2, when nested virtualization is used, local attackers could cause L1 KVM guests to VMEXIT, potentially allowing privilege escalations and denial of service attacks due to lack of checking of CPL."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"USN-3752-2","refsource":"UBUNTU","url":"https://usn.ubuntu.com/3752-2/"},{"name":"https://github.com/torvalds/linux/commit/727ba748e110b4de50d142edca9d6a9b7e6111d8","refsource":"MISC","url":"https://github.com/torvalds/linux/commit/727ba748e110b4de50d142edca9d6a9b7e6111d8"},{"name":"USN-3752-3","refsource":"UBUNTU","url":"https://usn.ubuntu.com/3752-3/"},{"name":"https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.17.2","refsource":"MISC","url":"https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.17.2"},{"name":"https://bugs.chromium.org/p/project-zero/issues/detail?id=1589","refsource":"MISC","url":"https://bugs.chromium.org/p/project-zero/issues/detail?id=1589"},{"name":"http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=727ba748e110b4de50d142edca9d6a9b7e6111d8","refsource":"MISC","url":"http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=727ba748e110b4de50d142edca9d6a9b7e6111d8"},{"name":"USN-3752-1","refsource":"UBUNTU","url":"https://usn.ubuntu.com/3752-1/"},{"name":"44944","refsource":"EXPLOIT-DB","url":"https://www.exploit-db.com/exploits/44944/"}]}},"nvd":{"publishedDate":"2018-06-27 11:29:00","lastModifiedDate":"2019-10-03 00:03:00","problem_types":["NVD-CWE-noinfo"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":4.9,"baseSeverity":"MEDIUM"},"exploitabilityScore":1.4,"impactScore":3.4},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:L/AC:M/Au:N/C:P/I:P/A:P","accessVector":"LOCAL","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":4.4},"severity":"MEDIUM","exploitabilityScore":3.4,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"4.17.2","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2018","CveId":"12904","Ordinal":"129551","Title":"CVE-2018-12904","CVE":"CVE-2018-12904","Year":"2018"},"notes":[{"CveYear":"2018","CveId":"12904","Ordinal":"1","NoteData":"In arch/x86/kvm/vmx.c in the Linux kernel before 4.17.2, when nested virtualization is used, local attackers could cause L1 KVM guests to VMEXIT, potentially allowing privilege escalations and denial of service attacks due to lack of checking of CPL.","Type":"Description","Title":null},{"CveYear":"2018","CveId":"12904","Ordinal":"2","NoteData":"2018-06-27","Type":"Other","Title":"Published"},{"CveYear":"2018","CveId":"12904","Ordinal":"3","NoteData":"2018-08-29","Type":"Other","Title":"Modified"}]}}}