CVE-2019-3887 PUBLISHED

A flaw was found in the way KVM hypervisor handled x2APIC Machine Specific Rregister (MSR) access with nested(=1) virtualization enabled. In that, L1 guest could access L0's APIC register values via L2 guest, when 'virtualize x2APIC mode' is enabled. A guest could use this flaw to potentially crash the host kernel resulting in DoS issue. Kernel versions from 4.16 and newer are vulnerable to this issue.

EPSS 0.04% · 10.9th percentile

Risk Scores

EPSS Score
0.04%
10.9th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSlinux-hwe4.18.0-18.19~18.04.1, 0, 4.18.0-13.14~18.04.1
Ubuntu:18.04:LTSlinux-gcp-edge0, 4.18.0-1004.5~18.04.1, 4.18.0-1005.6~18.04.1
Ubuntu:18.04:LTSlinux-azure4.15.0-1025.26, 4.15.0-1028.29, 4.15.0-1030.31

Timeline

References

Open in Interactive Console →