cbcvebase.
CVE-2017-12188
published 2017-10-11

CVE-2017-12188: arch/x86/kvm/mmu.c in the Linux kernel through 4.13.5, when nested virtualisation is used, does not properly traverse guest pagetable entries to resolve a…

PriorityP340high7.8CVSS 3.1
AVLACHPRLUINSCCHIHAH
EPSS
0.44%
35.8th percentile
arch/x86/kvm/mmu.c in the Linux kernel through 4.13.5, when nested virtualisation is used, does not properly traverse guest pagetable entries to resolve a guest virtual address, which allows L1 guest OS users to execute arbitrary code on the host OS or cause a denial of service (incorrect index during page walking, and host OS crash), aka an "MMU potential stack buffer overrun."

Affected

8 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 4.13.4-2 (bookworm)linux 4.13.4-2 (bookworm)
linuxlinux_kernel
linuxlinux_kernel>= 0 < 4.13.4-24.13.4-2
linuxlinux_kernel>= 0 < 4.13.4-24.13.4-2
linuxlinux_kernel>= 0 < 4.13.4-24.13.4-2
linuxlinux_kernel>= 0 < 4.13.4-24.13.4-2
linuxlinux_kernel>= 4.10 < 4.13.84.13.8
linuxlinux_kernel>= 4.6 < 4.9.574.9.57

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.