cbcvebase.
CVE-2022-1789
published 2022-06-02

CVE-2022-1789: With shadow paging enabled, the INVPCID instruction results in a call to kvm_mmu_invpcid_gva. If INVPCID is executed with CR0.PG=0, the invlpg callback is not…

medium6.8CVSS 3.1
AVPACLPRNUINSUCHIHAH
With shadow paging enabled, the INVPCID instruction results in a call to kvm_mmu_invpcid_gva. If INVPCID is executed with CR0.PG=0, the invlpg callback is not set and the result is a NULL pointer dereference.

Affected

14 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 5.17.11-1 (bookworm)linux 5.17.11-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
linuxlinux_kernel< 5.85.8
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.120-15.10.120-1
linuxlinux_kernel>= 0 < 5.17.11-15.17.11-1
linuxlinux_kernel>= 0 < 5.17.11-15.17.11-1
linuxlinux_kernel>= 0 < 5.17.11-15.17.11-1
linuxlinux_kernel>= 0 < 5.4.0-122.1385.4.0-122.138
linuxlinux_kernel>= 0 < 5.15.0-41.445.15.0-41.44
redhatenterprise_linux

CVSS provenance

nvdv3.16.8MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
cisa8.8HIGH