UBUNTU-CVE-2017-2596
The nested_vmx_check_vmptr function in arch/x86/kvm/vmx.c in the Linux kernel through 4.9.8 improperly emulates the VMXON instruction, which allows KVM L1 guest OS users to cause a denial of service (host OS memory consumption) by leveraging the mishandling of page references.
02 / AFFECTED SOFTWARE
Affected packages
30 explicit affected versions
52 explicit affected versions
10 explicit affected versions
8 explicit affected versions
17 explicit affected versions
28 explicit affected versions
25 explicit affected versions
26 explicit affected versions
51 explicit affected versions
6 explicit affected versions
12 explicit affected versions
1 explicit affected versions
1 explicit affected versions
23 explicit affected versions
1 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
The nested_vmx_check_vmptr function in arch/x86/kvm/vmx.c in the Linux kernel through 4.9.8 improperly emulates the VMXON instruction, which allows KVM L1 guest OS users to cause a denial of service (host OS memory consumption) by leveraging the mishandling of page references.
05 / REFERENCES
Further evidence
- https://bugzilla.redhat.com/show_bug.cgi?id=1417812
- https://ubuntu.com/security/CVE-2017-2596
- https://ubuntu.com/security/notices/USN-3293-1
- https://ubuntu.com/security/notices/USN-3312-1
- https://ubuntu.com/security/notices/USN-3312-2
- https://ubuntu.com/security/notices/USN-3361-1
- https://www.cve.org/CVERecord?id=CVE-2017-2596
- https://www.spinics.net/lists/kvm/msg144319.html