Kernel: kvm: nVMX: L2 guest may trick the L0 hypervisor to access sensitive L1 resources
Published Apr 8, 2020
6.8
MEDIUMCVSS 3.1
EPSS 0.93%
Description
A flaw was discovered in the way that the KVM hypervisor handled instruction emulation for an L2 guest when nested virtualisation is enabled. Under some circumstances, an L2 guest may trick the L0 guest into accessing sensitive L1 resources that should be inaccessible to the L2 guest.
Affected products
-
Affected
- 6
- 7
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Oracle Corporation | Oracle Linux | unknown | Affected
|
- 7.0
- 8.0
No data.
Red Hat Enterprise Linux 7
kernel-0:3.10.0-1160.el7
Fixed · RHSA-2020:4060
Red Hat Enterprise Linux 7
kernel-rt-0:3.10.0-1160.rt56.1131.el7
Fixed · RHSA-2020:4062
Red Hat Enterprise Linux 8
kernel-0:4.18.0-193.1.2.el8_2
Fixed · RHSA-2020:2102
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-193.1.2.rt13.53.el8_2
Fixed · RHSA-2020:2171
Red Hat Enterprise Linux 5
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-alt
Not affected
Red Hat Enterprise MRG 2
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | kernel-0:3.10.0-1160.el7 | Fixed | RHSA-2020:4060 |
| Red Hat Enterprise Linux 7 | kernel-rt-0:3.10.0-1160.rt56.1131.el7 | Fixed | RHSA-2020:4062 |
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-193.1.2.el8_2 | Fixed | RHSA-2020:2102 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-193.1.2.rt13.53.el8_2 | Fixed | RHSA-2020:2171 |
| Red Hat Enterprise Linux 5 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-alt | Not affected | n/a |
| Red Hat Enterprise MRG 2 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (18)
- https://access.redhat.com/security/cve/CVE-2020-2732 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1805135 x_refsource_MISCIssue TrackingThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-22525 Advisory
- https://git.kernel.org/linus/07721feee46b4b248402133228235318199b05ec x_refsource_MISCPatchThird Party Advisory
- https://git.kernel.org/linus/35a571346a94fb93b5b3b6a599675ef3384bc75c x_refsource_MISCPatchThird Party Advisory
- https://git.kernel.org/linus/e71237d3ff1abf9f3388337cfebf53b96df2020d x_refsource_MISCPatchThird Party Advisory
- https://linux.oracle.com/errata/ELSA-2020-5540.html x_refsource_MISCThird Party Advisory
- https://linux.oracle.com/errata/ELSA-2020-5542.html x_refsource_MISCThird Party Advisory
- https://linux.oracle.com/errata/ELSA-2020-5543.html x_refsource_MISCThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/06/msg00011.html mailing-listx_refsource_MLIST
- https://lists.debian.org/debian-lts-announce/2020/06/msg00012.html mailing-listx_refsource_MLIST
- https://lists.debian.org/debian-lts-announce/2020/06/msg00013.html mailing-listx_refsource_MLIST
- https://nvd.nist.gov/vuln/detail/CVE-2020-2732
- https://www.cve.org/CVERecord?id=CVE-2020-2732
- https://www.debian.org/security/2020/dsa-4667 vendor-advisoryx_refsource_DEBIAN
- https://www.debian.org/security/2020/dsa-4698 vendor-advisoryx_refsource_DEBIAN
- https://www.openwall.com/lists/oss-security/2020/02/25/3 x_refsource_MISCMailing ListThird Party Advisory
- https://www.spinics.net/lists/kvm/msg208259.html x_refsource_MISCPatchThird Party Advisory
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub
No data