CVE-2020-2732
published 2020-04-08CVE-2020-2732: A flaw was discovered in the way that the KVM hypervisor handled instruction emulation for an L2 guest when nested virtualisation is enabled. Under some…
PriorityP428medium6.8CVSS 3.1
AVAACLPRLUINSCCHINAN
EPSS
0.93%
56.5th percentile
A flaw was discovered in the way that the KVM hypervisor handled instruction emulation for an L2 guest when nested virtualisation is enabled. Under some circumstances, an L2 guest may trick the L0 guest into accessing sensitive L1 resources that should be inaccessible to the L2 guest.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.5.13-1 (bookworm) | linux 5.5.13-1 (bookworm) |
| linux | linux_kernel | >= 0 < 5.5.13-1 | 5.5.13-1 |
| linux | linux_kernel | >= 0 < 5.5.13-1 | 5.5.13-1 |
| linux | linux_kernel | >= 0 < 5.5.13-1 | 5.5.13-1 |
| linux | linux_kernel | >= 0 < 5.5.13-1 | 5.5.13-1 |
| linux | linux_kernel | >= 0 < 4.15.0-91.92 | 4.15.0-91.92 |
| oracle_corporation | oracle_linux | — | — |
| oracle_corporation | oracle_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.16.8MEDIUMCVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
nvdv2.02.3LOWAV:A/AC:M/Au:S/C:P/I:N/A:N
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian5.8MEDIUM
vendor_redhat5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2020-03-25·CVSS 5.5
CVE-2019-15217 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Paulo Bonzini discovered that the KVM hypervisor implementation in the
Linux kernel could improperly let a nested (level 2) guest access the
resources of a parent (level 1) guest in certain situations. An attacker
could use this to expose sensitive information. (CVE-2020-2732)
Gregory Herrero discovered that the fix for CVE-2019-14615 to address the
Linux kernel not properly clearing data structures on context switches for
certain Intel graphics processors was incomplete. A local attacker could
use this to expose sensitive information. (CVE-2020-8832)
It was discovered that the IPMI message handler implementation in the Linux
kernel did not properly deallocate memory in certain situatio
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2020-03-25·CVSS 4.6
CVE-2019-18809 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that the KVM implementation in the Linux kernel, when
paravirtual TLB flushes are enabled in guests, the hypervisor in some
situations could miss deferred TLB flushes or otherwise mishandle them. An
attacker in a guest VM could use this to expose sensitive information (read
memory from another guest VM). (CVE-2019-3016)
Paulo Bonzini discovered that the KVM hypervisor implementation in the
Linux kernel could improperly let a nested (level 2) guest access the
resources of a parent (level 1) guest in certain situations. An attacker
could use this to expose sensitive information. (CVE-2020-2732)
It was discovered that the Afatech AF9005 DVB-T USB device driver in the
Linu
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2020-03-25·CVSS 7.5
CVE-2019-19053 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that the KVM implementation in the Linux kernel, when
paravirtual TLB flushes are enabled in guests, the hypervisor in some
situations could miss deferred TLB flushes or otherwise mishandle them. An
attacker in a guest VM could use this to expose sensitive information (read
memory from another guest VM). (CVE-2019-3016)
Paulo Bonzini discovered that the KVM hypervisor implementation in the
Linux kernel could improperly let a nested (level 2) guest access the
resources of a parent (level 1) guest in certain situations. An attacker
could use this to expose sensitive information. (CVE-2020-2732)
It was discovered that the RPMSG character device interface in the Linux
kern
Ubuntu
Linux kernel (HWE) vulnerability
vendor_ubuntu·2020-03-17
CVE-2020-2732 Linux kernel (HWE) vulnerability
Title: Linux kernel (HWE) vulnerability
Summary: The system could be made to expose sensitive information.
USN-4303-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 ESM.
Paulo Bonzini discovered that the KVM hypervisor implementation in the
Linux kernel could improperly let a nested (level 2) guest access the
resources of a parent (level 1) guest in certain situations. An attacker
could use this to expose sensitive information.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number,
Ubuntu
Linux kernel vulnerability
vendor_ubuntu·2020-03-17
CVE-2020-2732 Linux kernel vulnerability
Title: Linux kernel vulnerability
Summary: The system could be made to expose sensitive information.
Paulo Bonzini discovered that the KVM hypervisor implementation in the
Linux kernel could improperly let a nested (level 2) guest access the
resources of a parent (level 1) guest in certain situations. An attacker
could use this to expose sensitive information.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, lin
Red Hat
Kernel: kvm: nVMX: L2 guest may trick the L0 hypervisor to access sensitive L1 resources
vendor_redhat·2020-02-24·CVSS 5.8
CVE-2020-2732 [MEDIUM] CWE-200 Kernel: kvm: nVMX: L2 guest may trick the L0 hypervisor to access sensitive L1 resources
Kernel: kvm: nVMX: L2 guest may trick the L0 hypervisor to access sensitive L1 resources
A flaw was discovered in the way that the KVM hypervisor handled instruction emulation for an L2 guest when nested virtualisation is enabled. Under some circumstances, an L2 guest may trick the L0 guest into accessing sensitive L1 resources that should be inaccessible to the L2 guest.
A flaw was found in the way KVM hypervisor handled instruction emulation for the L2 guest when nested(=1) virtualization is enabled. In the instruction emulation, the L2 guest could trick the L0 hypervisor into accessing sensitive bits of the L1 hypervisor. An L2 guest could use this flaw to potentially access information of the L1 hypervisor.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel
Debian
CVE-2020-2732: linux - A flaw was discovered in the way that the KVM hypervisor handled instruction emu...
vendor_debian·2020·CVSS 5.8
CVE-2020-2732 [MEDIUM] CVE-2020-2732: linux - A flaw was discovered in the way that the KVM hypervisor handled instruction emu...
A flaw was discovered in the way that the KVM hypervisor handled instruction emulation for an L2 guest when nested virtualisation is enabled. Under some circumstances, an L2 guest may trick the L0 guest into accessing sensitive L1 resources that should be inaccessible to the L2 guest.
Scope: local
bookworm: resolved (fixed in 5.5.13-1)
bullseye: resolved (fixed in 5.5.13-1)
forky: resolved (fixed in 5.5.13-1)
sid: resolved (fixed in 5.5.13-1)
trixie: resolved (fixed in 5.5.13-1)
GHSA
GHSA-pqrp-hrrg-q69p: A flaw was discovered in the way that the KVM hypervisor handled instruction emulation for an L2 guest when nested virtualisation is enabled
ghsa_unreviewed·2022-05-24
CVE-2020-2732 [LOW] GHSA-pqrp-hrrg-q69p: A flaw was discovered in the way that the KVM hypervisor handled instruction emulation for an L2 guest when nested virtualisation is enabled
A flaw was discovered in the way that the KVM hypervisor handled instruction emulation for an L2 guest when nested virtualisation is enabled. Under some circumstances, an L2 guest may trick the L0 guest into accessing sensitive L1 resources that should be inaccessible to the L2 guest.
OSV
CVE-2020-2732: A flaw was discovered in the way that the KVM hypervisor handled instruction emulation for an L2 guest when nested virtualisation is enabled
osv·2020-04-08·CVSS 6.8
CVE-2020-2732 [MEDIUM] CVE-2020-2732: A flaw was discovered in the way that the KVM hypervisor handled instruction emulation for an L2 guest when nested virtualisation is enabled
A flaw was discovered in the way that the KVM hypervisor handled instruction emulation for an L2 guest when nested virtualisation is enabled. Under some circumstances, an L2 guest may trick the L0 guest into accessing sensitive L1 resources that should be inaccessible to the L2 guest.
OSV
linux-aws-5.0, linux-gcp, linux-gke-5.0, linux-oracle-5.0, linux-azure vulnerabilities
osv·2020-03-25·CVSS 7.5
CVE-2019-3016 [HIGH] linux-aws-5.0, linux-gcp, linux-gke-5.0, linux-oracle-5.0, linux-azure vulnerabilities
linux-aws-5.0, linux-gcp, linux-gke-5.0, linux-oracle-5.0, linux-azure vulnerabilities
It was discovered that the KVM implementation in the Linux kernel, when
paravirtual TLB flushes are enabled in guests, the hypervisor in some
situations could miss deferred TLB flushes or otherwise mishandle them. An
attacker in a guest VM could use this to expose sensitive information (read
memory from another guest VM). (CVE-2019-3016)
Paulo Bonzini discovered that the KVM hypervisor implementation in the
Linux kernel could improperly let a nested (level 2) guest access the
resources of a parent (level 1) guest in certain situations. An attacker
could use this to expose sensitive information. (CVE-2020-2732)
It was discovered that the RPMSG character device interface in the Linux
kernel did not prop
OSV
linux, linux-aws, linux-gcp, linux-gcp-5.3, linux-gke-5.3, linux-hwe, linux-kvm, linux-oracle, linux-raspi2, linux-raspi2-5.3, linux-azure, linux-azure-5.3 vulnerabilities
osv·2020-03-25·CVSS 4.6
[MEDIUM] linux, linux-aws, linux-gcp, linux-gcp-5.3, linux-gke-5.3, linux-hwe, linux-kvm, linux-oracle, linux-raspi2, linux-raspi2-5.3, linux-azure, linux-azure-5.3 vulnerabilities
linux, linux-aws, linux-gcp, linux-gcp-5.3, linux-gke-5.3, linux-hwe, linux-kvm, linux-oracle, linux-raspi2, linux-raspi2-5.3, linux-azure, linux-azure-5.3 vulnerabilities
It was discovered that the KVM implementation in the Linux kernel, when
paravirtual TLB flushes are enabled in guests, the hypervisor in some
situations could miss deferred TLB flushes or otherwise mishandle them. An
attacker in a guest VM could use this to expose sensitive information (read
memory from another guest VM). (CVE-2019-3016)
Paulo Bonzini discovered that the KVM hypervisor implementation in the
Linux kernel could improperly let a nested (level 2) guest access the
resources of a parent (level 1) guest in certain situations. An attacker
could use this to expose sensitive information. (CVE-2020-2732)
It was
OSV
linux, linux-aws, linux-aws-hwe, linux-gcp, linux-gke-4.15, linux-hwe, linux-kvm, linux-oem, linux-oracle, linux-raspi2, linux-snapdragon, linux-azure vulnerabilities
osv·2020-03-25·CVSS 5.5
CVE-2020-2732 [MEDIUM] linux, linux-aws, linux-aws-hwe, linux-gcp, linux-gke-4.15, linux-hwe, linux-kvm, linux-oem, linux-oracle, linux-raspi2, linux-snapdragon, linux-azure vulnerabilities
linux, linux-aws, linux-aws-hwe, linux-gcp, linux-gke-4.15, linux-hwe, linux-kvm, linux-oem, linux-oracle, linux-raspi2, linux-snapdragon, linux-azure vulnerabilities
Paulo Bonzini discovered that the KVM hypervisor implementation in the
Linux kernel could improperly let a nested (level 2) guest access the
resources of a parent (level 1) guest in certain situations. An attacker
could use this to expose sensitive information. (CVE-2020-2732)
Gregory Herrero discovered that the fix for CVE-2019-14615 to address the
Linux kernel not properly clearing data structures on context switches for
certain Intel graphics processors was incomplete. A local attacker could
use this to expose sensitive information. (CVE-2020-8832)
It was discovered that the IPMI message handler implementation in the Li
Kernel
Merge tag 'for-linus' of git://git.kernel.org/pub/scm/virt/kvm/kvm
kernel_security·2020-02-24·CVSS 5.8
CVE-2020-2732 [MEDIUM] Merge tag 'for-linus' of git://git.kernel.org/pub/scm/virt/kvm/kvm
Merge tag 'for-linus' of git://git.kernel.org/pub/scm/virt/kvm/kvm
Pull kvm fixes from Paolo Bonzini:
"Bugfixes, including the fix for CVE-2020-2732 and a few issues found
by 'make W=1'"
* tag 'for-linus' of git://git.kernel.org/pub/scm/virt/kvm/kvm:
KVM: s390: rstify new ioctls in api.rst
KVM: nVMX: Check IO instruction VM-exit conditions
KVM: nVMX: Refactor IO bitmap checks into helper function
KVM: nVMX: Don't emulate instructions in guest mode
KVM: nVMX: Emulate MTF when performing instruction emulation
KVM: fix error handling in svm_hardware_setup
KVM: SVM: Fix potential memory leak in svm_cpu_init()
KVM: apic: avoid calculating pending eoi from an uninitialized val
KVM: nVMX: clear PIN_BASED_POSTED_INTR from nested pinbased_ctls only when apicv is globally disabled
KVM: nVMX: handl
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-12692 openstack-keystone: failure to check signature TTL of the EC2 credential auth method
bugzilla·2020-05-07·CVSS 5.4
CVE-2020-12692 [MEDIUM] CVE-2020-12692 openstack-keystone: failure to check signature TTL of the EC2 credential auth method
CVE-2020-12692 openstack-keystone: failure to check signature TTL of the EC2 credential auth method
https://bugs.launchpad.net/keystone/+bug/1872737
Discussion:
External References:
https://security.openstack.org/ossa/OSSA-2020-003.html
---
Patches are available for train/stein/rocky/pike from the upstream bug page (linked in the first comment)
---
Created openstack-keystone tracking bugs for this issue:
Affects: openstack-rdo [bug 1833168]
---
Acknowledgments:
Name: kay (OpenStack)
---
This issue has been addressed in the following products:
Red Hat OpenStack Platform 13.0 (Queens)
Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUS
Via RHSA-2020:2732 https://access.redhat.com/errata/RHSA-2020:2732
---
This bug is now closed. Further updates for individual products
Bugzilla
CVE-2020-2732 kernel: kvm: nVMX: L2 guest may trick the L0 hypervisor to access sensitive L1 resources [fedora-all]
bugzilla·2020-02-25·CVSS 5.8
CVE-2020-2732 [MEDIUM] CVE-2020-2732 kernel: kvm: nVMX: L2 guest may trick the L0 hypervisor to access sensitive L1 resources [fedora-all]
CVE-2020-2732 kernel: kvm: nVMX: L2 guest may trick the L0 hypervisor to access sensitive L1 resources [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this iss
Bugzilla
CVE-2020-2732 Kernel: kvm: nVMX: L2 guest may trick the L0 hypervisor to access sensitive L1 resources
bugzilla·2020-02-20·CVSS 5.8
CVE-2020-2732 [MEDIUM] CVE-2020-2732 Kernel: kvm: nVMX: L2 guest may trick the L0 hypervisor to access sensitive L1 resources
CVE-2020-2732 Kernel: kvm: nVMX: L2 guest may trick the L0 hypervisor to access sensitive L1 resources
Under certain circumstances, an L2 guest may trick the L0 hypervisor into accessing sensitive L1 resources that are supposed to be inaccessible to the L2 guest according to L1 hypervisor configuration.
Only Intel processors are affected. It requires netsted virtualization to be enabled, ie. kvm-intel.nested=1.
Upstream patch(es):
-> https://www.spinics.net/lists/kvm/msg208259.html
-> https://git.kernel.org/linus/07721feee46b4b248402133228235318199b05ec
-> https://git.kernel.org/linus/35a571346a94fb93b5b3b6a599675ef3384bc75c
-> https://git.kernel.org/linus/e71237d3ff1abf9f3388337cfebf53b96df2020d
Reference:
-> https://www.openwall.com/lists/oss-security/2020/02/25/3
Discussion:
Ackno
https://bugzilla.redhat.com/show_bug.cgi?id=1805135https://git.kernel.org/linus/07721feee46b4b248402133228235318199b05echttps://git.kernel.org/linus/35a571346a94fb93b5b3b6a599675ef3384bc75chttps://git.kernel.org/linus/e71237d3ff1abf9f3388337cfebf53b96df2020dhttps://linux.oracle.com/errata/ELSA-2020-5540.htmlhttps://linux.oracle.com/errata/ELSA-2020-5542.htmlhttps://linux.oracle.com/errata/ELSA-2020-5543.htmlhttps://lists.debian.org/debian-lts-announce/2020/06/msg00011.htmlhttps://lists.debian.org/debian-lts-announce/2020/06/msg00012.htmlhttps://lists.debian.org/debian-lts-announce/2020/06/msg00013.htmlhttps://www.debian.org/security/2020/dsa-4667https://www.debian.org/security/2020/dsa-4698https://www.openwall.com/lists/oss-security/2020/02/25/3https://www.spinics.net/lists/kvm/msg208259.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1805135https://git.kernel.org/linus/07721feee46b4b248402133228235318199b05echttps://git.kernel.org/linus/35a571346a94fb93b5b3b6a599675ef3384bc75chttps://git.kernel.org/linus/e71237d3ff1abf9f3388337cfebf53b96df2020dhttps://linux.oracle.com/errata/ELSA-2020-5540.htmlhttps://linux.oracle.com/errata/ELSA-2020-5542.htmlhttps://linux.oracle.com/errata/ELSA-2020-5543.htmlhttps://lists.debian.org/debian-lts-announce/2020/06/msg00011.htmlhttps://lists.debian.org/debian-lts-announce/2020/06/msg00012.htmlhttps://lists.debian.org/debian-lts-announce/2020/06/msg00013.htmlhttps://www.debian.org/security/2020/dsa-4667https://www.debian.org/security/2020/dsa-4698https://www.openwall.com/lists/oss-security/2020/02/25/3https://www.spinics.net/lists/kvm/msg208259.html
2020-04-08
Published