Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Speculative execution attacks in KVM VMX
Vulnerability Description
A regression exists in the Linux Kernel within KVM: nVMX that allowed for speculative execution attacks. L2 can carry out Spectre v2 attacks on L1 due to L1 thinking it doesn't need retpolines or IBPB after running L2 due to KVM (L0) advertising eIBRS support to L1. An attacker at L2 with code execution can execute code on an indirect branch on the host machine. We recommend upgrading to Kernel 6.2 or past commit 2e7eab81425a
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:L
Vulnerability Type
不安全的默认资源初始化
Vulnerability Title
Linux kernel 安全漏洞
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel 存在安全漏洞,该漏洞源于nVMX 允许推测执行攻击,L2 可以对 L1 执行 Spectre v2 攻击,因为 L1 认为它在运行 L2 后不需要 retpolines 或 IBPB,由于 KVM (L0) 向 L1 通告 eIBRS 支持,具有代码执行能力的 L2 攻击者可以在主机的间接分支上执行代码。
CVSS Information
N/A
Vulnerability Type
N/A