cbcvebase.
CVE-2017-12154
published 2017-09-26

CVE-2017-12154: The prepare_vmcs02 function in arch/x86/kvm/vmx.c in the Linux kernel through 4.13.3 does not ensure that the "CR8-load exiting" and "CR8-store exiting" L0…

PriorityP431high7.1CVSS 3.0
AVLACLPRLUINSUCHIHAN
EPSS
0.51%
40.8th percentile
The prepare_vmcs02 function in arch/x86/kvm/vmx.c in the Linux kernel through 4.13.3 does not ensure that the "CR8-load exiting" and "CR8-store exiting" L0 vmcs02 controls exist in cases where L1 omits the "use TPR shadow" vmcs12 control, which allows KVM L2 guest OS users to obtain read and write access to the hardware CR8 register.

Affected

7 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 4.12.13-1 (bookworm)linux 4.12.13-1 (bookworm)
linuxlinux_kernel<= 4.13.3
linuxlinux_kernel>= 0 < 4.12.13-14.12.13-1
linuxlinux_kernel>= 0 < 4.12.13-14.12.13-1
linuxlinux_kernel>= 0 < 4.12.13-14.12.13-1
linuxlinux_kernel>= 0 < 4.12.13-14.12.13-1
linuxlinux_kernel>= 0 < 3.13.0-153.2033.13.0-153.203

CVSS provenance

nvdv3.07.1HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
nvdv2.03.6LOWAV:L/AC:L/Au:N/C:P/I:P/A:N
osv7.1HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
vendor_ubuntu7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.