cbcvebase.
CVE-2023-30456
published 2023-04-10

CVE-2023-30456: An issue was discovered in arch/x86/kvm/vmx/nested.c in the Linux kernel before 6.2.8. nVMX on x86_64 lacks consistency checks for CR0 and CR4.

PriorityP421medium6.5CVSS 3.1
AVLACLPRLUINSCCNINAH
EPSS
0.47%
38.5th percentile
An issue was discovered in arch/x86/kvm/vmx/nested.c in the Linux kernel before 6.2.8. nVMX on x86_64 lacks consistency checks for CR0 and CR4.

Affected

22 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.25-1 (bookworm)linux 6.1.25-1 (bookworm)
linuxlinux_kernel< 6.2.86.2.8
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.178-15.10.178-1
linuxlinux_kernel>= 0 < 6.1.25-16.1.25-1
linuxlinux_kernel>= 0 < 6.1.25-16.1.25-1
linuxlinux_kernel>= 0 < 6.1.25-16.1.25-1
linuxlinux_kernel>= 0 < 4.15.0-212.2234.15.0-212.223
linuxlinux_kernel>= 0 < 5.4.0-150.1675.4.0-150.167
linuxlinux_kernel>= 0 < 5.15.0-73.805.15.0-73.80
linuxlinux_kernel>= 0 < 3.13.0-197.2483.13.0-197.248
linuxlinux_kernel>= 0 < 4.4.0-241.2754.4.0-241.275
linuxlinux_kernel>= 0 < 4.4.0-243.2774.4.0-243.277
linuxlinux_kernel>= 0 < 4.15.0-214.2254.15.0-214.225
linuxlinux_kernel>= 0 < 5.4.0-155.1725.4.0-155.172
linuxlinux_kernel>= 0 < 5.15.0-78.855.15.0-78.85
msrccbl2_kernel_5.15.107.1-2_on_cbl_mariner_2.0
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
msrccm1_kernel_5.10.177.1-1_on_cbl_mariner_1.0

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian6.5MEDIUM
vendor_msrc6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.