SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-39189

An issue was discovered the x86 KVM subsystem in the Linux kernel before 5.18.17.

HIGH 7.8EPSS 0.34%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.34%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

An issue was discovered the x86 KVM subsystem in the Linux kernel before 5.18.17. Unprivileged guest users can compromise the guest kernel because TLB flush operations are mishandled in certain KVM_VCPU_PREEMPTED situations.

CVSS 3.1
7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
0.34% probability · 27th percentile
CISA KEV
Not listed
Affected
linux/linux kernel · netapp/hci baseboard management controller
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.