ID:

CVE-2017-12188 (NVD)

- Vulnerability Info (edit)
2017-10-11

arch/x86/kvm/mmu.c in the Linux kernel through 4.13.5, when nested virtualisation is used, does not properly traverse guest pagetable entries to resolve a guest virtual address, which allows L1 guest OS users to execute arbitrary code on the host OS or cause a denial of service (incorrect index during page walking, and host OS crash), aka an "MMU potential stack buffer overrun."

Products Linux_kernel
Type Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
First patch - None (likely due to unavailable code)
Links https://access.redhat.com/errata/RHSA-2018:0412
http://www.securityfocus.com/bid/101267
https://bugzilla.redhat.com/show_bug.cgi?id=1500380
https://patchwork.kernel.org/patch/9996579/
https://patchwork.kernel.org/patch/9996587/
Annotation

Note:

No patch was assigned yet.