CVE-2018-12904

Description

De CVE.org

In arch/x86/kvm/vmx.c in the Linux kernel before 4.17.2, when nested virtualization is used, local attackers could cause L1 KVM guests to VMEXIT, potentially allowing privilege escalations and denial of service attacks due to lack of checking of CPL.

Déclaration

This issue does not affect the versions of the kernel package as shipped with Red Hat Enterprise Linux 5, 6, 7 and Red Hat Enterprise MRG 2.

Détails du score du système commun d'évaluation des vulnérabilités (CVSS)

Info alert:Important note

CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).

Les mesures et les scores CVSS suivants sont préliminaires et sujets à révision.

Répartition des scores CVSS v3

Red HatNVDcve.org
Score de base7.84.9N/A
Vecteur d'attaqueLocalLocalN/A
Complexité de l'attaqueHighHighN/A
Privilèges requisLowNoneN/A
Interaction avec l'utilisateurNoneNoneN/A
Champ d'applicationChangedUnchangedN/A
ConfidentialitéHighLowN/A
Impact sur l'intégritéHighLowN/A
Impact sur la disponibilitéHighLowN/A

Vecteur

Red Hat: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

NVD: CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L

Comprendre la Défaillance (CWE)

Other

Technical Impact: Varies by Context

Questions fréquemment posées

Vous souhaitez recevoir des notifications d'errata ? Signez ici.