Oval Definition:oval:com.ubuntu.artful:def:201712188000
Revision Date:2017-10-11Version:1
Title:CVE-2017-12188 on Ubuntu 17.10 (artful) - high.
Description:arch/x86/kvm/mmu.c in the Linux kernel through 4.13.5, when nested virtualisation is used, does not properly traverse guest pagetable entries to resolve a guest virtual address, which allows L1 guest OS users to execute arbitrary code on the host OS or cause a denial of service (incorrect index during page walking, and host OS crash), aka an "MMU potential stack buffer overrun." It was discovered that the KVM subsystem in the Linux kernel did not properly keep track of nested levels in guest page tables. A local attacker in a guest VM could use this to cause a denial of service (host OS crash) or possibly execute arbitrary code in the host OS.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2017-12188
Platform(s):Ubuntu 17.10
Product(s):
Definition Synopsis
  • Ubuntu 17.10 (artful) is installed.
  • AND Package Information
  • The 'linux' package in artful was vulnerable but has been fixed (note: '4.13.0-17.20').
  • OR The 'linux-raspi2' package in artful was vulnerable but has been fixed (note: '4.13.0-1006.6').
  • OR NOT While related to the CVE in some way, the 'linux-snapdragon' package in artful is not affected.
  • BACK