CVE-2019-3887: Canonical Ubuntu Linux

Medium severity, CVSS 5.6. EPSS: 0.4% chance of exploitation in the next 30 days.

A flaw was found in the way KVM hypervisor handled x2APIC Machine Specific Rregister (MSR) access with nested(=1) virtualization enabled. In that, L1 guest could access L0's APIC register values via L2 guest, when 'virtualize x2APIC mode' is enabled. A guest could use this flaw to potentially crash the host kernel resulting in DoS issue. Kernel versions from 4.16 and newer are vulnerable to this issue.

Affected products

  • Canonical Ubuntu Linux: version 18.04 only; version 18.10 only; version 19.04 only
  • Fedoraproject Fedora: version 29 only
  • Linux Linux Kernel: from 4.16
  • Red Hat Enterprise Linux: version 8.0 only
  • Red Hat Enterprise Linux Eus: version 8.1 only; version 8.2 only; version 8.4 only
  • Red Hat Enterprise Linux For Real Time: version 8 only
  • Red Hat Enterprise Linux For Real Time For Nfv: version 8 only
  • Red Hat Enterprise Linux For Real Time For Nfv Tus: version 8.2 only; version 8.4 only
  • Red Hat Enterprise Linux For Real Time Tus: version 8.2 only; version 8.4 only
  • Red Hat Enterprise Linux Server Aus: version 8.2 only; version 8.4 only
  • Red Hat Enterprise Linux Server Tus: version 8.2 only; version 8.4 only

Published 2019-04-09. Last modified 2026-06-17.