The apic_get_tmcct function in arch/x86/kvm/lapic.c in the KVM subsystem in the Linux kernel through 3.12.5 allows guest OS users to cause a denial of service (divide-by-zero error and host OS crash) via crafted modifications of the TMICT value.
Exploitability
AV:AAC:MAu:NImpact
C:NI:NA:C5.7/AV:A/AC:M/Au:N/C:N/I:N/A:C