Vulnerability Name:

CVE-2017-12188 (CCN-133522)

Assigned:2017-10-10
Published:2017-10-10
Updated:2023-02-12
Summary:arch/x86/kvm/mmu.c in the Linux kernel through 4.13.5, when nested virtualisation is used, does not properly traverse guest pagetable entries to resolve a guest virtual address, which allows L1 guest OS users to execute arbitrary code on the host OS or cause a denial of service (incorrect index during page walking, and host OS crash), aka an "MMU potential stack buffer overrun."
CVSS v3 Severity:7.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H)
6.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): High
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
7.8 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
6.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
7.6 High (REDHAT CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H)
6.6 Medium (REDHAT Temporal CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Adjacent
Attack Complexity (AC): High
Privileges Required (PR): High
User Interaction (UI): None
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:6.9 Medium (CVSS v2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
6.8 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:S/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
6.5 Medium (REDHAT CVSS v2 Vector: AV:A/AC:H/Au:S/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Adjacent_Network
Access Complexity (AC): High
Authentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-121
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2017-12188

Source: CCN
Type: BID-101267
Linux Kernel CVE-2017-12188 Remote Buffer Overflow Vulnerability

Source: secalert@redhat.com
Type: Third Party Advisory, VDB Entry
secalert@redhat.com

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: CCN
Type: Red Hat Bugzilla – Bug 1500380
(CVE-2017-12188) CVE-2017-12188 Kernel: KVM: MMU potential stack buffer overrun during page walks

Source: secalert@redhat.com
Type: Issue Tracking, Patch, Third Party Advisory
secalert@redhat.com

Source: XF
Type: UNKNOWN
linux-kernel-cve201712188-code-exec(133522)

Source: secalert@redhat.com
Type: Issue Tracking, Patch, Vendor Advisory
secalert@redhat.com

Source: secalert@redhat.com
Type: Issue Tracking, Patch, Vendor Advisory
secalert@redhat.com

Source: CCN
Type: Linux Kernel Web site
Linux Kernel

Vulnerable Configuration:Configuration RedHat 1:
  • cpe:/o:redhat:enterprise_linux:7:*:*:*:*:*:*:*
  • Configuration RedHat 2:
  • cpe:/o:redhat:enterprise_linux:7::client:*:*:*:*:*
  • Configuration RedHat 3:
  • cpe:/o:redhat:enterprise_linux:7::computenode:*:*:*:*:*
  • Configuration RedHat 4:
  • cpe:/o:redhat:enterprise_linux:7::server:*:*:*:*:*
  • Configuration RedHat 5:
  • cpe:/o:redhat:enterprise_linux:7::workstation:*:*:*:*:*
  • Configuration RedHat 6:
  • cpe:/a:redhat:rhel_extras_rt:7:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/o:linux:linux_kernel:4.13.5:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:201712188
    V
    CVE-2017-12188
    2023-02-13
    oval:org.opensuse.security:def:23999
    P
    Security update for java-1_7_0-openjdk (Important)
    2021-11-24
    oval:org.opensuse.security:def:46056
    P
    Security update for opensc (Important)
    2021-10-29
    oval:org.opensuse.security:def:61679
    P
    xorg-x11-7.6_1-1.22 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:61488
    P
    libXdmcp-devel-1.1.2-1.23 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:23963
    P
    Security update for file (Important)
    2021-09-02
    oval:org.opensuse.security:def:23951
    P
    Security update for MozillaFirefox (Important)
    2021-08-17
    oval:org.opensuse.security:def:62787
    P
    libgypsy-devel-0.9-2.30 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62329
    P
    squashfs-4.4-1.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62820
    P
    newt-devel-0.52.20-5.35 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62737
    P
    emacs-x11-25.3-3.6.51 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:23621
    P
    Security update for MozillaFirefox (Important)
    2021-07-16
    oval:org.opensuse.security:def:46837
    P
    rsync-3.1.0-2.7 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:46786
    P
    libxerces-c-3_1-3.1.1-4.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:61217
    P
    libXv-devel-1.0.11-1.23 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:23575
    P
    Security update for libxml2 (Important)
    2021-05-19
    oval:org.opensuse.security:def:23686
    P
    Security update for python3 (Important)
    2021-02-08
    oval:org.opensuse.security:def:45022
    P
    Security update for mutt (Moderate)
    2021-01-22
    oval:org.opensuse.security:def:23875
    P
    Security update for xen (Moderate)
    2020-12-22
    oval:org.opensuse.security:def:62688
    P
    libopenjpeg1-1.5.2-2.28 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62011
    P
    yast2-buildtools-4.2.5-1.45 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62650
    P
    libQt5OpenGLExtensions-devel-static-5.12.7-2.25 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:61806
    P
    libarchive-devel-3.4.2-2.24 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62558
    P
    libjbig2-32bit-2.1-1.31 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62457
    P
    libmpg123-0-1.25.10-1.38 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:61051
    P
    Security update for samba (Important)
    2020-12-01
    oval:org.opensuse.security:def:23328
    P
    Security update for patch (Important)
    2020-12-01
    oval:org.opensuse.security:def:45528
    P
    Security update for webkit2gtk3 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:23505
    P
    Security update for samba (Important)
    2020-12-01
    oval:org.opensuse.security:def:24669
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:61029
    P
    Security update for tomcat (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:45999
    P
    Security update for sqlite3 (Important)
    2020-12-01
    oval:org.opensuse.security:def:45447
    P
    Security update for java-1_8_0-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:23389
    P
    Security update for ucode-intel (Important)
    2020-12-01
    oval:org.opensuse.security:def:24637
    P
    Security update for libqt4 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:45326
    P
    Security update for tiff (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:23336
    P
    Security update for cairo (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:23828
    P
    Security update for libjpeg-turbo (Important)
    2020-12-01
    oval:org.opensuse.security:def:45144
    P
    Security update for java-1_8_0-openjdk (Important)
    2020-12-01
    oval:org.opensuse.security:def:61028
    P
    Security update for java-1_8_0-openjdk (Important)
    2020-12-01
    oval:org.opensuse.security:def:45941
    P
    Security update for spamassassin (Important)
    2020-12-01
    oval:org.opensuse.security:def:45034
    P
    Security update for java-1_7_1-ibm (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:46148
    P
    Security update for python-aws-sam-translator, python-boto3, python-botocore, python-cfn-lint, python-jsonschema, python-nose2, python-parameterized, python-pathlib2, python-pytest-cov, python-requests, python-s3transfer (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:45863
    P
    Security update for python3 (Important)
    2020-12-01
    oval:org.opensuse.security:def:45023
    P
    Security update for dovecot22 (Important)
    2020-12-01
    oval:org.opensuse.security:def:46085
    P
    Security update for apache2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:45657
    P
    Security update for binutils (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:87144
    P
    Security update for the Linux Kernel (Important)
    2020-06-09
    oval:com.redhat.rhsa:def:20180395
    P
    RHSA-2018:0395: kernel security and bug fix update (Important)
    2018-03-06
    oval:com.redhat.rhsa:def:20180412
    P
    RHSA-2018:0412: kernel-rt security and bug fix update (Important)
    2018-03-06
    oval:com.ubuntu.xenial:def:201712188000
    V
    CVE-2017-12188 on Ubuntu 16.04 LTS (xenial) - high.
    2017-10-11
    oval:com.ubuntu.xenial:def:2017121880000000
    V
    CVE-2017-12188 on Ubuntu 16.04 LTS (xenial) - high.
    2017-10-11
    oval:com.ubuntu.artful:def:201712188000
    V
    CVE-2017-12188 on Ubuntu 17.10 (artful) - high.
    2017-10-11
    oval:com.ubuntu.trusty:def:201712188000
    V
    CVE-2017-12188 on Ubuntu 14.04 LTS (trusty) - high.
    2017-10-11
    BACK
    linux linux kernel 4.13.5