arch/x86/entry/entry_64.S in the Linux kernel before 4.1.6 on the x86_64 platform improperly relies on espfix64 during nested NMI processing, which allows local users to gain privileges by triggering an NMI within a certain instruction window. http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-3290