CVE-2016-3713 PUBLISHED

The msr_mtrr_valid function in arch/x86/kvm/mtrr.c in the Linux kernel before 4.6.1 supports MSR 0x2f8, which allows guest OS users to read or write to the kvm_arch_vcpu data structure, and consequently obtain sensitive information or cause a denial of service (system crash), via a crafted ioctl call.

EPSS 0.06% · 18.4th percentile

Risk Scores

EPSS Score
0.06%
18.4th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSlinux4.4.0-22.39, 4.3.0-2.11, 4.3.0-5.16
Ubuntu:14.04:LTSlinux-lts-wily0, 4.2.0-19.23~14.04.1, 4.2.0-21.25~14.04.1
Ubuntu:14.04:LTSlinux-lts-xenial4.4.0-13.29~14.04.1, 4.4.0-14.30~14.04.2, 4.4.0-15.31~14.04.1

Timeline

References

Open in Interactive Console →