cbcvebase.
CVE-2015-0239
published 2015-03-02

CVE-2015-0239: The em_sysenter function in arch/x86/kvm/emulate.c in the Linux kernel before 3.18.5, when the guest OS lacks SYSENTER MSR initialization, allows guest OS…

PriorityP420medium4.4CVSS 2.0
AVLACMAuNCPIPAP
EPSS
0.64%
47.1th percentile
The em_sysenter function in arch/x86/kvm/emulate.c in the Linux kernel before 3.18.5, when the guest OS lacks SYSENTER MSR initialization, allows guest OS users to gain guest OS privileges or cause a denial of service (guest OS crash) by triggering use of a 16-bit code segment for emulation of a SYSENTER instruction.

Affected

19 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debianlinux< linux 3.16.7-ckt4-2 (bookworm)linux 3.16.7-ckt4-2 (bookworm)
linuxlinux_kernel< 3.18.53.18.5
linuxlinux_kernel>= 0 < 3.16.7-ckt4-23.16.7-ckt4-2
linuxlinux_kernel>= 0 < 3.16.7-ckt4-23.16.7-ckt4-2
linuxlinux_kernel>= 0 < 3.16.7-ckt4-23.16.7-ckt4-2
linuxlinux_kernel>= 0 < 3.16.7-ckt4-23.16.7-ckt4-2
linuxlinux_kernel>= 0 < 3.13.0-46.773.13.0-46.77
linuxlinux_kernel>= 0 < 3.13.0-46.753.13.0-46.75
linuxlinux_kernel>= 0 < 3.13.0-46.763.13.0-46.76
oraclelinux
oraclelinux
redhatenterprise_linux_desktop
redhatenterprise_linux_server
redhatenterprise_linux_workstation

CVSS provenance

nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
osv4.4MEDIUM
vendor_debian4.4MEDIUM
vendor_redhat4.4MEDIUM
vendor_ubuntu2.1LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.