Medium severity6.5NVD Advisory· Published Feb 6, 2017· Updated May 13, 2026
CVE-2017-2596
CVE-2017-2596
Description
The nested_vmx_check_vmptr function in arch/x86/kvm/vmx.c in the Linux kernel through 4.9.8 improperly emulates the VMXON instruction, which allows KVM L1 guest OS users to cause a denial of service (host OS memory consumption) by leveraging the mishandling of page references.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- www.openwall.com/lists/oss-security/2017/01/31/4nvdMailing ListPatchThird Party Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingPatch
- www.securityfocus.com/bid/95878nvdThird Party AdvisoryVDB Entry
- www.debian.org/security/2017/dsa-3791nvd
- access.redhat.com/errata/RHSA-2017:1842nvd
- access.redhat.com/errata/RHSA-2017:2077nvd
News mentions
0No linked articles in our index yet.