arch/x86/entry/entry_64.S in the Linux kernel before 4.1.6 on the x86_64 platform improperly relies on espfix64 during nested NMI processing, which allows local users to gain privileges by triggering an NMI within a certain instruction window.
Exploitability
AV:LAC:LAu:NImpact
C:CI:CA:C7.2/AV:L/AC:L/Au:N/C:C/I:C/A:C