Skip to content

kernel CVE-2022-1789

Moderate
rpkelly published GHSA-898x-fg76-8p5p Jul 29, 2022

Package

kernel-5.10 (bottlerocket)

Affected versions

< 1.9.0

Patched versions

1.9.0
kernel-5.15 (bottlerocket)
< 1.9.0
1.9.0

Description

A flaw was found in KVM. With shadow paging enabled if INVPCID is executed with CR0.PG=0, the invlpg callback is not set, and the result is a NULL pointer dereference. This flaw allows a guest user to cause a kernel oops condition on the host, resulting in a denial of service.

Severity

Moderate

CVE ID

CVE-2022-1789

Weaknesses

No CWEs