Total vulnerabilities in the database
A flaw was found in the way KVM hypervisor handled x2APIC Machine Specific Rregister (MSR) access with nested(=1) virtualization enabled. In that, L1 guest could access L0's APIC register values via L2 guest, when 'virtualize x2APIC mode' is enabled. A guest could use this flaw to potentially crash the host kernel resulting in DoS issue. Kernel versions from 4.16 and newer are vulnerable to this issue.
Software | From | Fixed in |
---|---|---|
linux / linux_kernel | 4.16 | 4.16.x |
fedoraproject / fedora | 29 | 29.x |
canonical / ubuntu_linux | 18.04 | 18.04.x |
canonical / ubuntu_linux | 18.10 | 18.10.x |
canonical / ubuntu_linux | 19.04 | 19.04.x |
redhat / enterprise_linux | 8.0 | 8.0.x |
redhat / enterprise_linux_eus | 8.1 | 8.1.x |
redhat / enterprise_linux_eus | 8.2 | 8.2.x |
redhat / enterprise_linux_server_tus | 8.2 | 8.2.x |
redhat / enterprise_linux_server_aus | 8.2 | 8.2.x |
redhat / enterprise_linux_for_real_time | 8 | 8.x |
redhat / enterprise_linux_server_tus | 8.4 | 8.4.x |
redhat / enterprise_linux_eus | 8.4 | 8.4.x |
redhat / enterprise_linux_for_real_time_for_nfv_tus | 8.4 | 8.4.x |
redhat / enterprise_linux_for_real_time_for_nfv_tus | 8.2 | 8.2.x |
redhat / enterprise_linux_for_real_time_tus | 8.4 | 8.4.x |
redhat / enterprise_linux_for_real_time_tus | 8.2 | 8.2.x |
redhat / enterprise_linux_server_aus | 8.4 | 8.4.x |
redhat / enterprise_linux_for_real_time_for_nfv | 8 | 8.x |