CVE-2016-4440: High severity linux kernel vulnerability
arch/x86/kvm/vmx.c in the Linux kernel through 4.6.3 mishandles the APICv on/off state, which allows guest OS users to obtain direct APIC MSR access on the host OS, and consequently cause a denial of service (host OS crash) or possibly execute arbitrary code on the host OS, via x2APIC mode.
Other sources
Linux kernel built with the Kernel-based virtual machine(CONFIGKVM) along with Hyper-v Synthetic Interrupt Controller(SynIC) support is vulnerable to an undue APIC register access issue. In that a guest with SynIC enabled, could gain access to host's Machine Specific Registers(MSR).
A privileged user inside guest could use this flaw to crash the host kernel resulting in DoS OR potentially leverage it to escalate privileges on the host.
Upstream patch: --------------- -> http://permalink.gmane.org/gmane.comp.emulators.kvm.devel/152191
Reference: ---------- -> http://comments.gmane.org/gmane.comp.emulators.kvm.devel/152100
Note: It requires fairly latest features to be available and enabled on the host(APICv) as well as in the guest(-hv-synic).
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-4440?
CVE-2016-4440 is classified as a high severity vulnerability due to its potential to allow denial of service or arbitrary code execution on the host OS.
How do I fix CVE-2016-4440?
To fix CVE-2016-4440, update your Linux kernel to version 4.7 or later.
What causes CVE-2016-4440?
CVE-2016-4440 is caused by mishandling of the APICv on/off state in the Linux kernel, allowing guest OS users unauthorized access to APIC MSRs.
Who is affected by CVE-2016-4440?
CVE-2016-4440 affects users running vulnerable versions of the Linux kernel from version 4.5 up to 4.6.3.
What are the potential impacts of CVE-2016-4440?
The potential impacts of CVE-2016-4440 include host OS crashes and the risk of arbitrary code execution by a guest OS.