Early Access — Mondoo Vulnerability Intelligence is currently in preview.
Maxim Levitsky discovered that the KVM hypervisor implementation for AMD processors in the Linux kernel did not properly prevent a guest VM from enabling AVIC in nested guest VMs. An attacker in a guest VM could use this to write to portions of the host's physical memory.
4.4.0-1096.1014.4.0-214.246~14.04.14.4.0-214.2464.4.0-1132.1464.4.0-1097.106