CVE-2019-3887

Aliases:DEBIAN-CVE-2019-3887CGA-26ph-pm52-w6p7CGA-27cf-qvm3-5r7pCGA-27r6-3rh9-4xg2CGA-2fx3-wwgh-v7c4CGA-2hvv-f7v2-73j2CGA-2mcm-gh49-93h5CGA-2vmq-j3fw-pcwrCGA-2xcr-rvjc-839wCGA-382f-fww5-4q8xCGA-384x-rr48-xc55CGA-3cfj-35fc-m8pcCGA-3jc6-6jcq-hhr5CGA-5256-gxpf-h2hqCGA-52h5-3jwc-h5gqCGA-53rc-c4fg-98qqCGA-5fgg-xp3p-2648CGA-5m65-fwvp-j74xCGA-673w-5v6w-qp6mCGA-67x4-c7ff-87hwCGA-68cr-v22w-2h66CGA-6945-p9fv-hchxCGA-6fp9-27mf-8qf3CGA-6gpm-cc9m-qj7mCGA-6vmp-hjcq-9f8jCGA-753w-vwp6-9fw2CGA-79wh-h49x-c75jCGA-7rh5-2gwx-38qcCGA-7x87-934r-5x4xCGA-822c-fwq6-x2g4CGA-82x8-pqxx-2gmgCGA-85xh-vw2q-xf9cCGA-88x9-pm8v-8qp8CGA-896j-wg28-ww6pCGA-8fc8-2r4f-6fmrCGA-8mvm-xwgh-jjmjCGA-8r32-jqwp-gf8wCGA-8v28-hv8w-52r2CGA-96mq-25qw-3mmjCGA-97j3-c9v6-xfr7CGA-97jg-9mj2-chxfCGA-9c43-4332-hfjhCGA-9cgf-mmx3-vr4cCGA-9mf6-hfjq-r7jmCGA-c5fv-4636-w768CGA-c7xr-v723-r4ghCGA-cc8x-q54c-9ghjCGA-cjf6-h3vj-p9vvCGA-crxh-mfp9-cmm7CGA-f5mp-8g7j-r29xCGA-fmjw-j7w7-x854CGA-g868-j8jf-4x86CGA-g87v-wj36-7c8hCGA-gpx6-fpcq-h325CGA-hcc8-gxj6-pw8mCGA-hj59-97j6-54xjCGA-hpmh-3jq8-v7j9CGA-j37f-6jhr-932wCGA-j4pf-5c28-2mf3CGA-jf4r-hp3v-h6w3CGA-jp8h-98w4-2vp6CGA-jrmq-47jh-gw7wCGA-jvq3-99rp-prp2CGA-jw33-93m6-jf8mCGA-jx6c-74vf-9xmfCGA-m244-jp98-7fg5CGA-m66r-99mm-mwg6CGA-mhmj-m6wx-g9qqCGA-mj5p-4pqf-pj88CGA-mv6r-8qf3-8xpcCGA-mxxh-rr65-7f7vCGA-p36f-crwm-hr5qCGA-p3px-w99c-q6f5CGA-p8f2-7xwg-4vcrCGA-p976-fg73-wh2gCGA-phwj-x4rw-886jCGA-pmg4-w8jp-xw7hCGA-pq8c-c228-w83jCGA-pqr6-jjr9-hcq9CGA-pv28-6cv4-r36xCGA-pxxm-q7v6-m5gpCGA-q66g-x9qm-99jfCGA-q89f-93j3-p639CGA-qg8p-4w96-jj8wCGA-qgw6-rjv2-634gCGA-qhch-fmq4-p22cCGA-qhfj-xr3m-wj2rCGA-qjq7-5qg4-w4f2CGA-qp7v-m7xg-h864CGA-qrq9-57g4-5hrcCGA-r6ww-5pcj-7fjjCGA-r7mj-86pv-j37pCGA-rcpv-g65h-vvp3CGA-rcxq-95v5-h8h5CGA-rghj-qpw9-gj48CGA-rm9p-xw33-6rghCGA-rmf6-8wvf-76r9CGA-rqp2-rfx8-hh75CGA-rw2x-382w-426rCGA-rw44-4rj3-pjm5CGA-rx6c-6vw3-qwhfCGA-vpvp-6pvc-g9xrCGA-w283-fwmr-w8mxCGA-w8vr-549x-qr79CGA-wfj7-h23p-c39xCGA-wrq6-x2fm-pqxfCGA-wwcj-phvv-hj5gCGA-x5mq-w854-455cCGA-xghq-mr32-jrq3CGA-xjx8-hjjq-9x95CGA-xphq-g5vq-34ggCGA-xppf-6799-q84mCGA-xqj8-9437-7cq6CGA-xv4x-f665-3fqrCGA-xx2j-fqx8-54gpCGA-c2pq-rcff-p2gcCGA-whgm-5m49-4gpfCGA-46wh-79wh-g9qqCGA-5rr6-6hpq-v7cpCGA-5w9g-936c-f3jmCGA-88xp-765m-8q86CGA-8p69-q9mj-7jxgCGA-cfgw-9367-7g4wCGA-gvph-r59v-36v5CGA-hq9c-f58g-3455CGA-m39p-vqff-8v6pCGA-qf55-p5v3-8c3jCGA-rqf7-3j3h-vj95CGA-vfjp-q5r4-mmcmCGA-vgj8-62cf-fhvrCGA-vm38-gfjj-gxj5CGA-w35c-r989-5389CGA-344q-9247-9g2jCGA-8px5-cmgr-rvmwCGA-9jgc-96c5-p6f5CGA-p6gc-2xrj-rrqgCGA-h2f7-675v-gjq3CGA-hhgr-vf43-q9xfCGA-wmr7-8f4g-w6ff
Modified
Published: 09 Apr 2019, 00:00
Last modified:04 Aug 2024, 19:19

Vulnerability Summary

Overall Risk (default)
medium
27/100
CVSS Score
6.7 MEDIUM
v3.0 (cve.org)
EPSS Score
0.36% LOW
0% probability +0.31%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

09 Apr 2019, 00:00
Published
Vulnerability first disclosed
04 Aug 2024, 19:19
Last Modified
Vulnerability information updated

Description

A flaw was found in the way KVM hypervisor handled x2APIC Machine Specific Rregister (MSR) access with nested(=1) virtualization enabled. In that, L1 guest could access L0's APIC register values via L2 guest, when 'virtualize x2APIC mode' is enabled. A guest could use this flaw to potentially crash the host kernel resulting in DoS issue. Kernel versions from 4.16 and newer are vulnerable to this issue.

CVSS Metrics

  • v3.1MEDIUMScore: 5.6CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H
  • v3.0MEDIUMScore: 6.7CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:H
  • v2.0MEDIUMScore: 4.7AV:L/AC:M/Au:N/C:N/I:N/A:C

EPSS Trends

Current EPSS score: 0.36% Percentile: 30%

Techniques & Countermeasures

  • CWE-863Incorrect Authorization

    The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Affected Systems

  • chainguardhyperv-daemons-6.18

    < 0

  • chainguardhyperv-daemons-generic

    < 0

  • chainguardlinux-aws-6.12

    < 0 | < 6.12.65-r0

  • chainguardlinux-aws-6.12-boot-installed

    < 0

  • chainguardlinux-aws-6.12-fips-boot-installed

    < 0

  • chainguardlinux-aws-6.12-headers

    < 0

  • chainguardlinux-aws-6.12-modules

    < 0

  • chainguardlinux-aws-6.18

    < 0 | < 6.18.10-r0

  • chainguardlinux-aws-6.18-boot-installed

    < 0

  • chainguardlinux-aws-6.18-fips-boot-installed

    < 0

  • chainguardlinux-aws-6.18-headers

    < 0

  • chainguardlinux-aws-6.18-modules

    < 0

  • chainguardlinux-aws-generic

    < 0 | < 6.18.5-r0

  • chainguardlinux-aws-generic-boot-installed

    < 0

  • chainguardlinux-aws-generic-fips-boot-installed

    < 0

  • chainguardlinux-aws-generic-headers

    < 0

  • chainguardlinux-aws-generic-modules

    < 0

  • chainguardlinux-azure-6.12

    < 0 | < 6.12.65-r1

  • chainguardlinux-azure-6.18

    < 0

  • chainguardlinux-azure-6.18-boot-installed

    < 0

  • chainguardlinux-azure-6.18-fips-boot-installed

    < 0

  • chainguardlinux-azure-6.18-headers

    < 0

  • chainguardlinux-azure-6.18-modules

    < 0

  • chainguardlinux-azure-generic

    < 6.18.5-r0 | < 0

  • chainguardlinux-azure-generic-boot-installed

    < 0

  • chainguardlinux-azure-generic-fips-boot-installed

    < 0

  • chainguardlinux-azure-generic-headers

    < 0

  • chainguardlinux-azure-generic-modules

    < 0

  • chainguardlinux-desktop-6.18

    all

  • chainguardlinux-desktop-6.18-bootc

    all

  • chainguardlinux-desktop-6.18-bootc-boot-installed

    all

  • chainguardlinux-desktop-6.18-headers

    all

  • chainguardlinux-desktop-6.18-modules

    all

  • chainguardlinux-desktop-7.2

    all

  • chainguardlinux-desktop-7.2-bootc

    all

  • chainguardlinux-desktop-7.2-modules

    all

  • chainguardlinux-firecracker-6.18

    all

  • chainguardlinux-gcp-6.12

    < 0 | < 6.12.65-r0

  • chainguardlinux-gcp-6.18

    < 6.18.10-r0 | < 0

  • chainguardlinux-gcp-6.18-boot-installed

    < 0

  • chainguardlinux-gcp-6.18-fips-boot-installed

    < 0

  • chainguardlinux-gcp-6.18-headers

    < 0

  • chainguardlinux-gcp-6.18-modules

    < 0

  • chainguardlinux-gcp-generic

    < 6.18.5-r0 | < 0

  • chainguardlinux-gcp-generic-boot-installed

    < 0

  • chainguardlinux-gcp-generic-fips-boot-installed

    < 0

  • chainguardlinux-gcp-generic-headers

    < 0

  • chainguardlinux-gcp-generic-modules

    < 0

  • chainguardlinux-qemu-6.12

    < 6.12.71-r0

  • chainguardlinux-qemu-6.18

    < 6.18.10-r0

Showing first 50 affected entries in server-rendered view.

References (9)