VDB

DEBIAN-CVE-2018-12904

DEBIAN-CVE-2018-12904 PUBLISHED CVSS 4.900000095367432 MEDIUM

In arch/x86/kvm/vmx.c in the Linux kernel before 4.17.2, when nested virtualization is used, local attackers could cause L1 KVM guests to VMEXIT, potentially allowing privilege escalations and denial of service attacks due to lack of checking of CPL.

Risk Scores

CVSS v3.0
4.900000095367432
CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L

Affected Products

VendorProductVersions
Debian:11linux0, 0, 0
Debian:12linux0, 0, 0
Debian:13linux0, 0, 0
Debian:14linux0, 0, 0

Timeline

  • Jun 27, 2018 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›