Skip to content

kernel CVE-2022-2153

Moderate
rpkelly published GHSA-3rg2-x5gq-4xgg Jan 27, 2023

Package

kernel-5.10 (bottlerocket)

Affected versions

< 1.12.0

Patched versions

1.12.0

Description

A flaw was found in the Linux kernel's KVM when attempting to set a SynIC IRQ. This issue makes it possible for a misbehaving VMM to write to SYNIC/STIMER MSRs, causing a NULL pointer dereference. This flaw allows an unprivileged local user to issue specific ioctl calls, causing a kernel oops condition that results in a denial of service.

Severity

Moderate

CVE ID

CVE-2022-2153

Weaknesses

No CWEs