CVE-2019-3887: Canonical Ubuntu Linux
Medium severity, CVSS 5.6. EPSS: 0.4% chance of exploitation in the next 30 days.
A flaw was found in the way KVM hypervisor handled x2APIC Machine Specific Rregister (MSR) access with nested(=1) virtualization enabled. In that, L1 guest could access L0's APIC register values via L2 guest, when 'virtualize x2APIC mode' is enabled. A guest could use this flaw to potentially crash the host kernel resulting in DoS issue. Kernel versions from 4.16 and newer are vulnerable to this issue.
Affected products
- Canonical Ubuntu Linux: version 18.04 only; version 18.10 only; version 19.04 only
- Fedoraproject Fedora: version 29 only
- Linux Linux Kernel: from 4.16
- Red Hat Enterprise Linux: version 8.0 only
- Red Hat Enterprise Linux Eus: version 8.1 only; version 8.2 only; version 8.4 only
- Red Hat Enterprise Linux For Real Time: version 8 only
- Red Hat Enterprise Linux For Real Time For Nfv: version 8 only
- Red Hat Enterprise Linux For Real Time For Nfv Tus: version 8.2 only; version 8.4 only
- Red Hat Enterprise Linux For Real Time Tus: version 8.2 only; version 8.4 only
- Red Hat Enterprise Linux Server Aus: version 8.2 only; version 8.4 only
- Red Hat Enterprise Linux Server Tus: version 8.2 only; version 8.4 only
Published 2019-04-09. Last modified 2026-06-17.