Skip to content

kernel CVE-2022-0171

Moderate
rpkelly published GHSA-5qr2-h2m2-hp3p Jan 27, 2023

Package

kernel-5.10 (bottlerocket)

Affected versions

< 1.12.0

Patched versions

1.12.0
kernel-5.15 (bottlerocket)
< 1.12.0
1.12.0

Description

The existing KVM SEV API has a vulnerability that allows a non-root (host) user-level application to crash the host kernel by creating a confidential guest VM instance in AMD CPU that supports Secure Encrypted Virtualization (SEV).

Severity

Moderate

CVE ID

CVE-2022-0171

Weaknesses

No CWEs