VulnerabilityModified
CVE-2022-39189
An issue was discovered the x86 KVM subsystem in the Linux kernel before 5.18.17.
HIGH 7.8EPSS 0.34%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.34%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An issue was discovered the x86 KVM subsystem in the Linux kernel before 5.18.17. Unprivileged guest users can compromise the guest kernel because TLB flush operations are mishandled in certain KVM_VCPU_PREEMPTED situations.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.34% probability · 27th percentile
- CISA KEV
- Not listed
- Affected
- linux/linux kernel · netapp/hci baseboard management controller
- Source
- cve@mitre.org
References
- https://bugs.chromium.org/p/project-zero/issues/detail?id=2309Issue Tracking, Patch, Third Party Advisory
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.18.17Patch, Release Notes, Vendor Advisory
- https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=6cd88243c7e03845a450795e134b488fc2afb736Patch, Vendor Advisory
- https://github.com/torvalds/linux/commit/6cd88243c7e03845a450795e134b488fc2afb736Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/10/msg00027.html
- https://security.netapp.com/advisory/ntap-20230214-0007/Third Party Advisory
- https://www.debian.org/security/2023/dsa-5480Third Party Advisory, VDB Entry
- https://bugs.chromium.org/p/project-zero/issues/detail?id=2309Issue Tracking, Patch, Third Party Advisory
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.18.17Patch, Release Notes, Vendor Advisory
- https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=6cd88243c7e03845a450795e134b488fc2afb736Patch, Vendor Advisory
- https://github.com/torvalds/linux/commit/6cd88243c7e03845a450795e134b488fc2afb736Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/10/msg00027.html
- https://security.netapp.com/advisory/ntap-20230214-0007/Third Party Advisory
- https://www.debian.org/security/2023/dsa-5480Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.