CVE-2022-1158Use After Free in Kernel

Severity
7.8HIGHNVD
OSV6.5OSV4.4
EPSS
0.0%
top 94.84%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 5
Latest updateFeb 14

Description

A flaw was found in KVM. When updating a guest's page table entry, vm_pgoff was improperly used as the offset to get the page's pfn. As vaddr and vm_pgoff are controllable by user-mode processes, this flaw allows unprivileged local users on the host to write outside the userspace region and potentially corrupt the kernel, resulting in a denial of service condition.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages5 packages

NVDlinux/linux_kernel5.25.4.189+4
Debianlinux/linux_kernel< 5.10.113-1+3
Ubuntulinux/linux_kernel< 5.4.0-117.132+1
CVEListV5linux/linux_kernelkernel 5.18
Palo Altopaloalto/pan-os

Also affects: Fedora 36, Enterprise Linux 8.0, 9.0

🔴Vulnerability Details

7
OSV
CVE-2022-1158: A flaw was found in KVM2022-08-05
CVEList
CVE-2022-1158: A flaw was found in KVM2022-08-05
OSV
linux, linux-aws, linux-aws-5.4, linux-azure, linux-azure-5.4, linux-azure-fde, linux-gcp, linux-gcp-5.4, linux-gke, linux-gke-5.4, linux-gkeop, linux-gkeop-5.4, linux-hwe-5.4, linux-ibm, linux-ibm-5.2022-06-08
OSV
linux, linux-aws, linux-aws-5.13, linux-azure, linux-azure-5.13, linux-gcp, linux-gcp-5.13, linux-hwe-5.13, linux-intel-5.13, linux-kvm, linux-oracle, linux-oracle-5.13, linux-raspi vulnerabilities2022-06-08
OSV
linux, linux-aws, linux-azure, linux-gcp, linux-gke, linux-ibm, linux-intel-iotg, linux-kvm, linux-lowlatency, linux-oracle, linux-raspi vulnerabilities2022-06-08

📋Vendor Advisories

9
Palo Alto
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS2024-02-14
Microsoft
A flaw was found in KVM. When updating a guest's page table entry vm_pgoff was improperly used as the offset to get the page's pfn. As vaddr and vm_pgoff are controllable by user-mode processes this f2022-08-09
Ubuntu
Linux kernel vulnerabilities2022-06-08
Ubuntu
Linux kernel vulnerabilities2022-06-08
Ubuntu
Linux kernel vulnerabilities2022-06-08
CVE-2022-1158 — Use After Free in Linux Kernel | cvebase