CVE-2017-7518 is a privilege escalation vulnerability in the Linux kernel's KVM module, affecting versions prior to 4.12, specifically impacting non-Linux guests. The flaw allows a low-privileged user within a guest VM to escalate their privileges by manipulating the trap flag during syscall emulation. With a CVSS score of 7.8 (High), this vulnerability has a local attack vector and high impact on confidentiality, integrity, and availability. There is no evidence of active exploitation, public exploit code, or significant community discussion, suggesting a low current threat level.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:* | ||
7.4CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_server_aus:7.4:*:*:*:*:*:*:* | ||
7.4CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_server_eus:7.4:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.