kernel CVE-2022-2196
Package
kernel-5.10
(bottlerocket)
Affected versions
< 1.13.3
Patched versions
1.13.3
kernel-5.15
(bottlerocket)
< 1.13.3
1.13.3
A flaw was found in the KVM's Intel nested virtualization feature (nVMX). Since L1 and L2 shared branch prediction modes (guest-user and guest-kernel), KVM did not protect indirect branches in L1 from actions in L2. This flaw could lead to code execution on an indirect branch on the host machine.