ISOMAN

CVE

CVE-2019-3887

A flaw was found in the way KVM hypervisor handled x2APIC Machine Specific Rregister (MSR) access with nested(=1) virtualization enabled. In that, L1 guest could access L0's APIC register values via L2 guest, when 'virtualize x2APIC mode' is enabled. A guest could use this flaw to potentially crash the host kernel resulting in DoS issue. Kernel versions from 4.16 and newer are vulnerable to this issue.

Severity
MEDIUM
CVSS
5.6
Published
Modified

Linked Releases

DistributionReleaseStatusEvidence
Ubuntu18.04.6 amd64 desktopunknownsource
Ubuntu18.04.6 amd64 live-serverunknownsource

References

  1. http://www.securityfocus.com/bid/107850
  2. https://access.redhat.com/errata/RHSA-2019:2703
  3. https://access.redhat.com/errata/RHSA-2019:2741
  4. https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3887
  5. https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IWPOIII2L73HV5PGXSGMRMKQIK47UIYE/
  6. https://usn.ubuntu.com/3979-1/
  7. https://usn.ubuntu.com/3980-1/
  8. https://usn.ubuntu.com/3980-2/
  9. http://www.securityfocus.com/bid/107850
  10. https://access.redhat.com/errata/RHSA-2019:2703
  11. https://access.redhat.com/errata/RHSA-2019:2741
  12. https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3887
  13. https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IWPOIII2L73HV5PGXSGMRMKQIK47UIYE/
  14. https://usn.ubuntu.com/3979-1/
  15. https://usn.ubuntu.com/3980-1/
  16. https://usn.ubuntu.com/3980-2/