CVE-2017-12188

high
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

arch/x86/kvm/mmu.c in the Linux kernel through 4.13.5, when nested virtualisation is used, does not properly traverse guest pagetable entries to resolve a guest virtual address, which allows L1 guest OS users to execute arbitrary code on the host OS or cause a denial of service (incorrect index during page walking, and host OS crash), aka an "MMU potential stack buffer overrun."

References

http://www.securityfocus.com/bid/101267

https://access.redhat.com/errata/RHSA-2018:0395

https://access.redhat.com/errata/RHSA-2018:0412

https://bugzilla.redhat.com/show_bug.cgi?id=1500380

https://patchwork.kernel.org/patch/9996579/

https://patchwork.kernel.org/patch/9996587/

Details

Source: MITRE

Published: 2017-10-11

Updated: 2018-03-08

Type: CWE-22

Risk Information

CVSS v2

Base Score: 6.9

Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Impact Score: 10

Exploitability Score: 3.4

Severity: MEDIUM

CVSS v3

Base Score: 7.8

Vector: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

Impact Score: 6

Exploitability Score: 1.1

Severity: HIGH

Vulnerable Software

Configuration 1

OR

cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions up to 4.13.5 (inclusive)

Tenable Plugins

View all (18 total)

IDNameProductFamilySeverity
127165NewStart CGSL MAIN 5.04 : kernel Multiple Vulnerabilities (NS-SA-2019-0014)NessusNewStart CGSL Local Security Checks
high
124982EulerOS Virtualization for ARM 64 3.0.1.0 : kernel (EulerOS-SA-2019-1529)NessusHuawei Local Security Checks
medium
124821EulerOS Virtualization 3.0.1.0 : kernel (EulerOS-SA-2019-1498)NessusHuawei Local Security Checks
high
121754Photon OS 2.0: Linux PHSA-2017-0043NessusPhotonOS Local Security Checks
high
111892Photon OS 2.0: Linux PHSA-2017-0043 (deprecated)NessusPhotonOS Local Security Checks
high
107271CentOS 7 : kernel (CESA-2018:0395)NessusCentOS Local Security Checks
high
107210Scientific Linux Security Update : kernel on SL7.x x86_64 (20180306)NessusScientific Linux Local Security Checks
high
107203Oracle Linux 7 : kernel (ELSA-2018-0395)NessusOracle Linux Local Security Checks
high
107189RHEL 7 : kernel-rt (RHSA-2018:0412)NessusRed Hat Local Security Checks
high
107186RHEL 7 : kernel (RHSA-2018:0395)NessusRed Hat Local Security Checks
high
104911EulerOS 2.0 SP2 : kernel (EulerOS-SA-2017-1292)NessusHuawei Local Security Checks
medium
104738Ubuntu 16.04 LTS : linux-azure vulnerability (USN-3488-1)NessusUbuntu Local Security Checks
high
104737Ubuntu 17.10 : linux, linux-raspi2 vulnerabilities (USN-3487-1)NessusUbuntu Local Security Checks
high
104734Ubuntu 16.04 LTS : linux-gcp vulnerability (USN-3484-3)NessusUbuntu Local Security Checks
high
104715Ubuntu 16.04 LTS : linux-hwe vulnerability (USN-3484-2)NessusUbuntu Local Security Checks
high
104714Ubuntu 17.04 : linux, linux-raspi2 vulnerability (USN-3484-1)NessusUbuntu Local Security Checks
high
104296EulerOS 2.0 SP1 : kernel (EulerOS-SA-2017-1271)NessusHuawei Local Security Checks
high
104132Virtuozzo 7 : readykernel-patch (VZA-2017-098)NessusVirtuozzo Local Security Checks
high