CVE-2020-2732

medium
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

A flaw was discovered in the way that the KVM hypervisor handled instruction emulation for an L2 guest when nested virtualisation is enabled. Under some circumstances, an L2 guest may trick the L0 guest into accessing sensitive L1 resources that should be inaccessible to the L2 guest.

References

https://bugzilla.redhat.com/show_bug.cgi?id=1805135

https://git.kernel.org/linus/07721feee46b4b248402133228235318199b05ec

https://git.kernel.org/linus/35a571346a94fb93b5b3b6a599675ef3384bc75c

https://git.kernel.org/linus/e71237d3ff1abf9f3388337cfebf53b96df2020d

https://linux.oracle.com/errata/ELSA-2020-5540.html

https://linux.oracle.com/errata/ELSA-2020-5542.html

https://linux.oracle.com/errata/ELSA-2020-5543.html

https://lists.debian.org/debian-lts-announce/2020/06/msg00011.html

https://lists.debian.org/debian-lts-announce/2020/06/msg00012.html

https://lists.debian.org/debian-lts-announce/2020/06/msg00013.html

https://www.debian.org/security/2020/dsa-4667

https://www.debian.org/security/2020/dsa-4698

https://www.openwall.com/lists/oss-security/2020/02/25/3

https://www.spinics.net/lists/kvm/msg208259.html

Details

Source: MITRE

Published: 2020-04-08

Updated: 2020-06-10

Type: CWE-200

Risk Information

CVSS v2

Base Score: 2.3

Vector: AV:A/AC:M/Au:S/C:P/I:N/A:N

Impact Score: 2.9

Exploitability Score: 4.4

Severity: LOW

CVSS v3

Base Score: 6.8

Vector: CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

Impact Score: 4

Exploitability Score: 2.3

Severity: MEDIUM

Tenable Plugins

View all (42 total)

IDNameProductFamilySeverity
149336NewStart CGSL CORE 5.04 / MAIN 5.04 : kernel Multiple Vulnerabilities (NS-SA-2021-0025)NessusNewStart CGSL Local Security Checks
medium
146181EulerOS 2.0 SP5 : kernel (EulerOS-SA-2021-1200)NessusHuawei Local Security Checks
high
145913CentOS 8 : kernel (CESA-2020:2102)NessusCentOS Local Security Checks
high
141727Scientific Linux Security Update : kernel on SL7.x x86_64 (20201001)NessusScientific Linux Local Security Checks
high
141619CentOS 7 : kernel (CESA-2020:4060)NessusCentOS Local Security Checks
high
141057RHEL 7 : kernel (RHSA-2020:4060)NessusRed Hat Local Security Checks
high
141026RHEL 7 : kernel-rt (RHSA-2020:4062)NessusRed Hat Local Security Checks
high
138766NewStart CGSL MAIN 6.01 : kernel Multiple Vulnerabilities (NS-SA-2020-0030)NessusNewStart CGSL Local Security Checks
critical
138272SUSE SLES15 Security Update : kernel (SUSE-SU-2020:1663-1)NessusSuSE Local Security Checks
critical
137516EulerOS 2.0 SP2 : kernel (EulerOS-SA-2020-1674)NessusHuawei Local Security Checks
critical
137340Debian DSA-4698-1 : linux - security updateNessusDebian Local Security Checks
medium
137339Debian DLA-2242-1 : linux-4.9 security updateNessusDebian Local Security Checks
medium
137283Debian DLA-2241-2 : linux security updateNessusDebian Local Security Checks
medium
136782SUSE SLES12 Security Update : kernel (SUSE-SU-2020:1275-1) (MDSUM/RIDL) (MFBDS/RIDL/ZombieLoad) (MLPDS/RIDL) (MSBDS/Fallout)NessusSuSE Local Security Checks
critical
136661SUSE SLES12 Security Update : kernel (SUSE-SU-2020:1255-1)NessusSuSE Local Security Checks
critical
136646Oracle Linux 8 : kernel (ELSA-2020-2102)NessusOracle Linux Local Security Checks
high
136611RHEL 8 : kernel-rt (RHSA-2020:2171)NessusRed Hat Local Security Checks
medium
136526RHEL 8 : kernel (RHSA-2020:2102)NessusRed Hat Local Security Checks
high
136239EulerOS Virtualization for ARM 64 3.0.2.0 : kernel (EulerOS-SA-2020-1536)NessusHuawei Local Security Checks
critical
136166SUSE SLES12 Security Update : kernel (SUSE-SU-2020:1142-1)NessusSuSE Local Security Checks
high
136124Debian DSA-4667-1 : linux - security updateNessusDebian Local Security Checks
high
135936Amazon Linux AMI : kernel (ALAS-2020-1360)NessusAmazon Linux Local Security Checks
medium
135525EulerOS 2.0 SP3 : kernel (EulerOS-SA-2020-1396)NessusHuawei Local Security Checks
critical
135155EulerOS Virtualization for ARM 64 3.0.6.0 : kernel (EulerOS-SA-2020-1368)NessusHuawei Local Security Checks
high
134971Slackware 14.2 : Slackware 14.2 kernel (SSA:2020-086-01)NessusSlackware Local Security Checks
critical
134896Amazon Linux 2 : kernel (ALAS-2020-1405)NessusAmazon Linux Local Security Checks
medium
134784EulerOS 2.0 SP8 : kernel (EulerOS-SA-2020-1292)NessusHuawei Local Security Checks
high
134661Ubuntu 16.04 LTS : Linux kernel vulnerability (USN-4303-1)NessusUbuntu Local Security Checks
medium
134660Ubuntu 16.04 LTS / 18.04 LTS : Linux kernel vulnerabilities (USN-4302-1)NessusUbuntu Local Security Checks
medium
134659Ubuntu 18.04 LTS : Linux kernel vulnerabilities (USN-4301-1)NessusUbuntu Local Security Checks
medium
134658Ubuntu 18.04 LTS / 19.10 : Linux kernel vulnerabilities (USN-4300-1)NessusUbuntu Local Security Checks
medium
134624SUSE SLED15 / SLES15 Security Update : kernel (SUSE-SU-2020:0688-1)NessusSuSE Local Security Checks
high
134559openSUSE Security Update : the Linux Kernel (openSUSE-2020-336)NessusSuSE Local Security Checks
critical
134293SUSE SLES12 Security Update : kernel (SUSE-SU-2020:0584-1)NessusSuSE Local Security Checks
critical
134289SUSE SLED15 / SLES15 Security Update : kernel (SUSE-SU-2020:0560-1)NessusSuSE Local Security Checks
critical
134288SUSE SLES12 Security Update : kernel (SUSE-SU-2020:0559-1)NessusSuSE Local Security Checks
critical
134287SUSE SLES12 Security Update : kernel (SUSE-SU-2020:0558-1)NessusSuSE Local Security Checks
critical
134255Fedora 30 : kernel (2020-fe00e12580)NessusFedora Local Security Checks
medium
134247Fedora 31 : kernel (2020-227a4c0530)NessusFedora Local Security Checks
medium
134061Oracle Linux 6 / 7 : Unbreakable Enterprise kernel (ELSA-2020-5543)NessusOracle Linux Local Security Checks
medium
134060Oracle Linux 6 / 7 : Unbreakable Enterprise kernel (ELSA-2020-5542)NessusOracle Linux Local Security Checks
medium
134023Oracle Linux 7 : Unbreakable Enterprise kernel (ELSA-2020-5540)NessusOracle Linux Local Security Checks
medium