CVE-2020-2732

Published Apr 8, 2020

Last updated 4 years ago

Overview

Description
A flaw was discovered in the way that the KVM hypervisor handled instruction emulation for an L2 guest when nested virtualisation is enabled. Under some circumstances, an L2 guest may trick the L0 guest into accessing sensitive L1 resources that should be inaccessible to the L2 guest.
Source
secalert_us@oracle.com
NVD status
Modified

Social media

Hype score
Not currently trending

Risk scores

CVSS 3.1

Type
Primary
Base score
6.8
Impact score
4
Exploitability score
2.3
Vector string
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Severity
MEDIUM

CVSS 2.0

Type
Primary
Base score
2.3
Impact score
2.9
Exploitability score
4.4
Vector string
AV:A/AC:M/Au:S/C:P/I:N/A:N

Weaknesses

nvd@nist.gov
CWE-200

Configurations