CVE-2022-3344Expected Behavior Violation in Kernel

Severity
5.5MEDIUMNVD
EPSS
0.1%
top 71.29%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 25
Latest updateFeb 26

Description

A flaw was found in the KVM's AMD nested virtualization (SVM). A malicious L1 guest could purposely fail to intercept the shutdown of a cooperative nested guest (L2), possibly leading to a page fault and kernel panic in the host (L0).

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages7 packages

Debianlinux/linux_kernel< 6.0.12-1+2
Ubuntulinux/linux_kernel< 5.15.0-67.74
CVEListV5linux/linux_kernelAffected versions <= 6.0.3

Patches

🔴Vulnerability Details

10
OSV
linux-intel-iotg vulnerabilities2023-03-16
OSV
linux-kvm vulnerabilities2023-03-09
OSV
linux-gkeop vulnerabilities2023-03-08
OSV
linux-ibm, linux-raspi vulnerabilities2023-03-07
OSV
linux, linux-aws, linux-aws-5.15, linux-azure, linux-azure-5.15, linux-azure-fde, linux-gcp, linux-gcp-5.15, linux-gke, linux-gke-5.15, linux-hwe-5.15, linux-lowlatency, linux-lowlatency-hwe-5.15, lin2023-03-02

📋Vendor Advisories

12
Red Hat
kernel: ext4: fix race condition between ext4_write and ext4_convert_inline_data2025-02-26
Ubuntu
Linux kernel (Intel IoTG) vulnerabilities2023-03-16
Ubuntu
Linux kernel (KVM) vulnerabilities2023-03-14
Ubuntu
Linux kernel (KVM) vulnerabilities2023-03-09
Ubuntu
Linux kernel (GKE) vulnerabilities2023-03-08