CVE-2017-8106 - CVE House
Back to Database
Status published Medium CVE-2017-8106

The handle_invept function in arch/x86/kvm/vmx.c in the Linux kernel 3.12...

Vulnerability Description

The handle_invept function in arch/x86/kvm/vmx.c in the Linux kernel 3.12 through 3.15 allows privileged KVM guest OS users to cause a denial of service (NULL pointer dereference and host OS crash) via a single-context INVEPT instruction with a NULL EPT pointer.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2017-8106

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

linux kernel
Vulnerable Versions:
3.12, 3.12.1, 3.12.2, 3.12.3, 3.12.4, 3.12.5, 3.12.6, 3.12.7, 3.12.8, 3.12.9, 3.12.10, 3.12.11, 3.12.12, 3.12.13, 3.12.14, 3.12.15, 3.12.16, 3.12.17, 3.12.18, 3.12.19, 3.12.20, 3.12.21, 3.12.22, 3.12.23, 3.12.24, 3.12.25, 3.12.26, 3.12.27, 3.12.28, 3.12.29, 3.12.30, 3.12.31, 3.12.32, 3.12.33, 3.12.34, 3.12.35, 3.12.36, 3.12.37, 3.12.38, 3.12.39, 3.12.40, 3.12.41, 3.12.42, 3.12.43, 3.12.44, 3.12.45, 3.12.46, 3.12.47, 3.12.48, 3.12.49, 3.12.50, 3.12.51, 3.12.52, 3.12.53, 3.12.54, 3.12.55, 3.12.56, 3.12.57, 3.12.58, 3.12.59, 3.13, 3.14.67, 3.14.68, 3.15

Timeline

Official Publish: April 24th, 2017
Last Modified: September 16th, 2024
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.