CVE-2018-12904 is a vulnerability in the Linux kernel, specifically affecting nested virtualization in KVM on x86 architectures before version 4.17.2. Local attackers within an L1 KVM guest can trigger VMEXITs due to insufficient checking of the Current Privilege Level (CPL), impacting various Canonical and Linux kernel versions. This vulnerability has a CVSS score of 4.9 (Medium), indicating a local attack vector with high attack complexity. Successful exploitation could lead to privilege escalation and denial of service within the affected guest, with low impacts on confidentiality, integrity, and availability. While there is no evidence of active exploitation or Metasploit/Nuclei modules, an exploit (EDB-44944) is available on ExploitDB. The CVE has received minimal community discussion and media coverage, suggesting it is not widely publicized or actively targeted.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.17.2CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
16.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:* | ||
18.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.