Forum Discussion

Peter_Baumann's avatar
Peter_Baumann
Icon for Cirrostratus rankCirrostratus
Mar 19, 2020

CVE-2020-2732 Flaw in KVM Hypervisor

Hello F5,

There is the new CVE-2020-2732, a flaw in KVM Hypervisor.

See here : https://access.redhat.com/security/cve/cve-2020-2732

 

"A flaw was found in the way KVM hypervisor handled instruction emulation for the L2 guest when nested(=1) virtualization is enabled. In the instruction emulation, the L2 guest could trick the L0 hypervisor into accessing sensitive bits of the L1 hypervisor. An L2 guest could use this flaw to potentially access information of the L1 hypervisor."

 

I cannot find any information from F5 about this CVE.

What about Viprion Systems according to this CVE-2020-2732?

 

Thanks for your update.

 

Best regards,

Peter

3 Replies

  • ,

    Thanks, I opened a case and today I got the answer that the product development team confirmed that CVE-2020-2732 is not affecting any Big-IP product.

  • if you have a support contract i would raise a ticket about this, chance on a reply here is small until an official K article is created, which will probably be sooner if tickets get opened on it.