kernel CVE-2022-1789
Package
kernel-5.10
(bottlerocket)
Affected versions
< 1.9.0
Patched versions
1.9.0
kernel-5.15
(bottlerocket)
< 1.9.0
1.9.0
A flaw was found in KVM. With shadow paging enabled if INVPCID is executed with CR0.PG=0, the invlpg callback is not set, and the result is a NULL pointer dereference. This flaw allows a guest user to cause a kernel oops condition on the host, resulting in a denial of service.