Description
An issue was discovered in arch/x86/kvm/vmx/nested.c in the Linux kernel before 6.2.8. nVMX on x86_64 lacks consistency checks for CR0 and CR4.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:HExploitability: 2.0 | Impact: 4.0Attack Vector: Local
Complexity: Low
Privileges: Low
User Interaction: None
Scope: Changed
Confidentiality: None
Integrity: None
Availability: High
Affected Packages10 packages
🔴Vulnerability Details
17OSVlinux vulnerabilities↗2024-03-18 ▶ OSVlinux-iot vulnerabilities↗2023-07-27 ▶ OSVKernel Live Patch Security Notice↗2023-07-25 ▶ OSVlinux-xilinx-zynqmp vulnerabilities↗2023-07-12 ▶ OSVlinux-intel-iotg-5.15 vulnerabilities↗2023-06-14 ▶ 📋Vendor Advisories
18UbuntuLinux kernel vulnerabilities↗2024-03-18 ▶ UbuntuLinux kernel (IoT) vulnerabilities↗2023-07-27 ▶ UbuntuKernel Live Patch Security Notice↗2023-07-25 ▶ UbuntuLinux kernel (Xilinx ZynqMP) vulnerabilities↗2023-07-12 ▶ UbuntuLinux kernel vulnerabilities↗2023-06-22 ▶ 📄Research Papers
1arXivNecoFuzz: Effective Fuzzing of Nested Virtualization via Fuzz-Harness Virtual Machines↗2025-12-09 ▶ 💬Community
1BugzillaCVE-2023-30456 kernel: KVM: nVMX: missing consistency checks for CR0 and CR4↗2023-04-20 ▶