CVE-2017-12188: Linux Kernel
High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.
arch/x86/kvm/mmu.c in the Linux kernel through 4.13.5, when nested virtualisation is used, does not properly traverse guest pagetable entries to resolve a guest virtual address, which allows L1 guest OS users to execute arbitrary code on the host OS or cause a denial of service (incorrect index during page walking, and host OS crash), aka an "MMU potential stack buffer overrun."
Affected products
- Linux Linux Kernel: from 4.6, before 4.9.57 (fixed in 4.9.57); from 4.10, before 4.13.8 (fixed in 4.13.8)
Published 2017-10-11. Last modified 2026-06-17.