FlawAtlas
Search the atlas
UBUNTU-CVE-2017-2596 Moderate

UBUNTU-CVE-2017-2596

The nested_vmx_check_vmptr function in arch/x86/kvm/vmx.c in the Linux kernel through 4.9.8 improperly emulates the VMXON instruction, which allows KVM L1 guest OS users to cause a denial of service (host OS memory consumption) by leveraging the mishandling of page references.

Exploit probability Not scored
Published February 6, 2017
Required by Not available
Last source change April 22, 2026

02 / AFFECTED SOFTWARE

Affected packages

Ubuntu:14.04:LTS linux-lts-xenial

30 explicit affected versions

Ubuntu:16.04:LTS linux

52 explicit affected versions

Ubuntu:16.04:LTS linux-aws

10 explicit affected versions

Ubuntu:16.04:LTS linux-gke

8 explicit affected versions

Ubuntu:16.04:LTS linux-hwe

17 explicit affected versions

Ubuntu:16.04:LTS linux-raspi2

28 explicit affected versions

Ubuntu:16.04:LTS linux-snapdragon

25 explicit affected versions

Ubuntu:20.04:LTS linux-azure-fde

26 explicit affected versions

Ubuntu:20.04:LTS linux-gke

51 explicit affected versions

Ubuntu:20.04:LTS linux-raspi2

6 explicit affected versions

Ubuntu:20.04:LTS linux-riscv

12 explicit affected versions

Ubuntu:22.04:LTS linux-intel-iot-realtime

1 explicit affected versions

Ubuntu:22.04:LTS linux-realtime

1 explicit affected versions

Ubuntu:22.04:LTS linux-riscv

23 explicit affected versions

Ubuntu:24.04:LTS linux-raspi-realtime

1 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

related USN-3293-1

04 / EVIDENCE

Source records

Open Source Vulnerabilities UBUNTU-CVE-2017-2596

The nested_vmx_check_vmptr function in arch/x86/kvm/vmx.c in the Linux kernel through 4.9.8 improperly emulates the VMXON instruction, which allows KVM L1 guest OS users to cause a denial of service (host OS memory consumption) by leveraging the mishandling of page references.

View original source

05 / REFERENCES

Further evidence