CVE-2017-12168
published 2017-09-20CVE-2017-12168: The access_pmu_evcntr function in arch/arm64/kvm/sys_regs.c in the Linux kernel before 4.8.11 allows privileged KVM guest OS users to cause a denial of service…
PriorityP419medium6CVSS 3.1
AVLACLPRHUINSCCNINAH
EPSS
0.42%
34.3th percentile
The access_pmu_evcntr function in arch/arm64/kvm/sys_regs.c in the Linux kernel before 4.8.11 allows privileged KVM guest OS users to cause a denial of service (assertion failure and host OS crash) by accessing the Performance Monitors Cycle Count Register (PMCCNTR).
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.8.11-1 (bookworm) | linux 4.8.11-1 (bookworm) |
| linux | linux_kernel | <= 4.8.10 | — |
| linux | linux_kernel | >= 0 < 4.8.11-1 | 4.8.11-1 |
| linux | linux_kernel | >= 0 < 4.8.11-1 | 4.8.11-1 |
| linux | linux_kernel | >= 0 < 4.8.11-1 | 4.8.11-1 |
| linux | linux_kernel | >= 0 < 4.8.11-1 | 4.8.11-1 |
CVSS provenance
nvdv3.16.0MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv6.0MEDIUM
vendor_debian6.0MEDIUM
vendor_redhat6.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2017-12168: linux - The access_pmu_evcntr function in arch/arm64/kvm/sys_regs.c in the Linux kernel ...
vendor_debian·2017·CVSS 6.0
CVE-2017-12168 [MEDIUM] CVE-2017-12168: linux - The access_pmu_evcntr function in arch/arm64/kvm/sys_regs.c in the Linux kernel ...
The access_pmu_evcntr function in arch/arm64/kvm/sys_regs.c in the Linux kernel before 4.8.11 allows privileged KVM guest OS users to cause a denial of service (assertion failure and host OS crash) by accessing the Performance Monitors Cycle Count Register (PMCCNTR).
Scope: local
bookworm: resolved (fixed in 4.8.11-1)
bullseye: resolved (fixed in 4.8.11-1)
forky: resolved (fixed in 4.8.11-1)
sid: resolved (fixed in 4.8.11-1)
trixie: resolved (fixed in 4.8.11-1)
Red Hat
Kernel: kvm: ARM64: assert failure when accessing PMCCNTR register
vendor_redhat·2016-11-18·CVSS 6.0
CVE-2017-12168 [MEDIUM] CWE-617 Kernel: kvm: ARM64: assert failure when accessing PMCCNTR register
Kernel: kvm: ARM64: assert failure when accessing PMCCNTR register
The access_pmu_evcntr function in arch/arm64/kvm/sys_regs.c in the Linux kernel before 4.8.11 allows privileged KVM guest OS users to cause a denial of service (assertion failure and host OS crash) by accessing the Performance Monitors Cycle Count Register (PMCCNTR).
An assertion failure issue was found in the Linux kernel's KVM hypervisor module built to support visualization on ARM64 architecture platforms. The failure could occur while accessing Performance Monitors Cycle Count Register (PMCCNTR) from a guest. A privileged guest user could use this flaw to crash the host kernel resulting in denial of service.
Statement: This issue does not affect the versions of the kernel package as shipped with Red Hat Enterprise Li
GHSA
GHSA-2rfq-4jx8-3hp9: The access_pmu_evcntr function in arch/arm64/kvm/sys_regs
ghsa_unreviewed·2022-05-13
CVE-2017-12168 [MEDIUM] CWE-617 GHSA-2rfq-4jx8-3hp9: The access_pmu_evcntr function in arch/arm64/kvm/sys_regs
The access_pmu_evcntr function in arch/arm64/kvm/sys_regs.c in the Linux kernel before 4.8.11 allows privileged KVM guest OS users to cause a denial of service (assertion failure and host OS crash) by accessing the Performance Monitors Cycle Count Register (PMCCNTR).
OSV
CVE-2017-12168: The access_pmu_evcntr function in arch/arm64/kvm/sys_regs
osv·2017-09-20·CVSS 6.0
CVE-2017-12168 [MEDIUM] CVE-2017-12168: The access_pmu_evcntr function in arch/arm64/kvm/sys_regs
The access_pmu_evcntr function in arch/arm64/kvm/sys_regs.c in the Linux kernel before 4.8.11 allows privileged KVM guest OS users to cause a denial of service (assertion failure and host OS crash) by accessing the Performance Monitors Cycle Count Register (PMCCNTR).
No detection rules found.
No public exploits indexed.
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=9e3f7a29694049edd728e2400ab57ad7553e5aa9http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.8.11https://bugzilla.redhat.com/show_bug.cgi?id=1492984https://github.com/torvalds/linux/commit/9e3f7a29694049edd728e2400ab57ad7553e5aa9http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=9e3f7a29694049edd728e2400ab57ad7553e5aa9http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.8.11https://bugzilla.redhat.com/show_bug.cgi?id=1492984https://github.com/torvalds/linux/commit/9e3f7a29694049edd728e2400ab57ad7553e5aa9
2017-09-20
Published