CVE-2017-8106: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.

The handle_invept function in arch/x86/kvm/vmx.c in the Linux kernel 3.12 through 3.15 allows privileged KVM guest OS users to cause a denial of service (NULL pointer dereference and host OS crash) via a single-context INVEPT instruction with a NULL EPT pointer.

Affected products

  • Linux Linux Kernel: version 3.12 only; version 3.12.1 only; version 3.12.2 only; version 3.12.3 only; version 3.12.4 only; version 3.12.5 only; …

Published 2017-04-24. Last modified 2026-06-17.