Skip to content

kernel CVE-2022-39189

Moderate
rpkelly published GHSA-68xf-h3vm-p665 Jan 27, 2023

Package

kernel-5.15 (bottlerocket)

Affected versions

< 1.12.0

Patched versions

1.12.0

Description

A flaw was found in the x86 KVM subsystem in kvm_steal_time_set_preempted in arch/x86/kvm/x86.c in the Linux kernel. Unprivileged guest users can compromise the guest kernel because TLB flush operations are mishandled in certain KVM_VCPU_PREEMPTED situations.

Severity

Moderate

CVE ID

CVE-2022-39189

Weaknesses

No CWEs