A flaw was discovered in the way that the KVM hypervisor handled instruction emulation for an L2 guest when nested virtualisation is enabled. Under some circumstances, an L2 guest may trick the L0 guest into accessing sensitive L1 resources that should be inaccessible to the L2 guest.
                
            Metrics
Affected Vendors & Products
Advisories
    | Source | ID | Title | 
|---|---|---|
|  Debian DLA | DLA-2241-1 | linux security update | 
|  Debian DLA | DLA-2241-2 | linux security update | 
|  Debian DLA | DLA-2242-1 | linux-4.9 security update | 
|  Debian DSA | DSA-4667-1 | linux security update | 
|  Debian DSA | DSA-4698-1 | linux security update | 
|  EUVD | EUVD-2020-22525 | A flaw was discovered in the way that the KVM hypervisor handled instruction emulation for an L2 guest when nested virtualisation is enabled. Under some circumstances, an L2 guest may trick the L0 guest into accessing sensitive L1 resources that should be inaccessible to the L2 guest. | 
|  Ubuntu USN | USN-4300-1 | Linux kernel vulnerabilities | 
|  Ubuntu USN | USN-4301-1 | Linux kernel vulnerabilities | 
|  Ubuntu USN | USN-4302-1 | Linux kernel vulnerabilities | 
|  Ubuntu USN | USN-4303-1 | Linux kernel vulnerability | 
|  Ubuntu USN | USN-4303-2 | Linux kernel (HWE) vulnerability | 
Fixes
    Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
        History
                    Mon, 30 Sep 2024 16:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: oracle
Published:
Updated: 2024-09-30T15:47:44.316Z
Reserved: 2019-12-10T00:00:00
Link: CVE-2020-2732
 Vulnrichment
                        Vulnrichment
                    Updated: 2024-08-04T07:17:02.148Z
 NVD
                        NVD
                    Status : Modified
Published: 2020-04-08T22:15:12.263
Modified: 2024-11-21T05:26:06.910
Link: CVE-2020-2732
 Redhat
                        Redhat
                     OpenCVE Enrichment
                        OpenCVE Enrichment
                    No data.