The kvm_apic_has_events function in arch/x86/kvm/lapic.h in the Linux kernel through 4.1.3 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by leveraging /dev/kvm access for an ioctl call. <a href"http://cwe.mitre.org/data/definitions/476.html">CWE-476: NULL Pointer Dereference</a>
Publication date: Mon, 27 Jul 2015 15:59:00 +0000