5.5
CVSSv3

CVE-2017-8106

Published: 24/04/2017 Updated: 05/05/2017
CVSS v2 Base Score: 4.9 | Impact Score: 6.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 436
Vector: AV:L/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

The handle_invept function in arch/x86/kvm/vmx.c in the Linux kernel 3.12 up to and including 3.15 allows privileged KVM guest OS users to cause a denial of service (NULL pointer dereference and host OS crash) via a single-context INVEPT instruction with a NULL EPT pointer.

Vulnerable Product Search on Vulmon Subscribe to Product

linux linux kernel 3.12

linux linux kernel 3.12.5

linux linux kernel 3.12.7

linux linux kernel 3.12.14

linux linux kernel 3.12.16

linux linux kernel 3.12.23

linux linux kernel 3.12.25

linux linux kernel 3.12.27

linux linux kernel 3.12.29

linux linux kernel 3.12.36

linux linux kernel 3.12.38

linux linux kernel 3.12.45

linux linux kernel 3.12.47

linux linux kernel 3.12.52

linux linux kernel 3.12.54

linux linux kernel 3.12.9

linux linux kernel 3.12.10

linux linux kernel 3.12.11

linux linux kernel 3.12.12

linux linux kernel 3.14.67

linux linux kernel 3.14.68

linux linux kernel 3.15

linux linux kernel 3.12.26

linux linux kernel 3.12.40

linux linux kernel 3.12.41

linux linux kernel 3.12.42

linux linux kernel 3.12.43

linux linux kernel 3.12.56

linux linux kernel 3.12.57

linux linux kernel 3.12.58

linux linux kernel 3.12.59

linux linux kernel 3.13

linux linux kernel 3.12.1

linux linux kernel 3.12.2

linux linux kernel 3.12.3

linux linux kernel 3.12.4

linux linux kernel 3.12.18

linux linux kernel 3.12.19

linux linux kernel 3.12.20

linux linux kernel 3.12.21

linux linux kernel 3.12.31

linux linux kernel 3.12.32

linux linux kernel 3.12.33

linux linux kernel 3.12.34

linux linux kernel 3.12.35

linux linux kernel 3.12.48

linux linux kernel 3.12.49

linux linux kernel 3.12.50

linux linux kernel 3.12.51

linux linux kernel 3.12.6

linux linux kernel 3.12.8

linux linux kernel 3.12.13

linux linux kernel 3.12.15

linux linux kernel 3.12.17

linux linux kernel 3.12.22

linux linux kernel 3.12.24

linux linux kernel 3.12.28

linux linux kernel 3.12.30

linux linux kernel 3.12.37

linux linux kernel 3.12.39

linux linux kernel 3.12.44

linux linux kernel 3.12.46

linux linux kernel 3.12.53

linux linux kernel 3.12.55

Vendor Advisories

The handle_invept function in arch/x86/kvm/vmxc in the Linux kernel 312 through 315 allows privileged KVM guest OS users to cause a denial of service (NULL pointer dereference and host OS crash) via a single-context INVEPT instruction with a NULL EPT pointer ...