linux linux-kernel CVE-2019-3887 vulnerability in Linux and Other Products
Published on April 9, 2019

product logo product logo product logo product logo
A flaw was found in the way KVM hypervisor handled x2APIC Machine Specific Rregister (MSR) access with nested(=1) virtualization enabled. In that, L1 guest could access L0's APIC register values via L2 guest, when 'virtualize x2APIC mode' is enabled. A guest could use this flaw to potentially crash the host kernel resulting in DoS issue. Kernel versions from 4.16 and newer are vulnerable to this issue.

Vendor Advisory Vendor Advisory Vendor Advisory Vendor Advisory Vendor Advisory Vendor Advisory NVD

Weakness Type

What is an AuthZ Vulnerability?

The software performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.

CVE-2019-3887 has been classified to as an AuthZ vulnerability or weakness.


Products Associated with CVE-2019-3887

You can be notified by email with stack.watch whenever vulnerabilities like CVE-2019-3887 are published in these products:

 
 
 
 
 
 
 
 
 
 
 

Affected Versions

The Linux Foundation Kernel Version from 4.16 is affected by CVE-2019-3887

Exploit Probability

EPSS
0.05%
Percentile
15.29%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.