7.8

CVE-2022-39189

An issue was discovered the x86 KVM subsystem in the Linux kernel before 5.18.17. Unprivileged guest users can compromise the guest kernel because TLB flush operations are mishandled in certain KVM_VCPU_PREEMPTED situations.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 4.16 < 5.4.244
Linux ≫ Linux Kernel Version >= 5.5.0 < 5.10.180
Linux ≫ Linux Kernel Version >= 5.11 < 5.15.60
Linux ≫ Linux Kernel Version >= 5.16 < 5.18.17
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.33% 0.255
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA-ADP 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://bugs.chromium.org/p/project-zero/issues/detail?id=2309
Patch
Third Party Advisory
Issue Tracking
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.18.17
Patch
Vendor Advisory
Release Notes
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=6cd88243c7e03845a450795e134b488fc2afb736
Patch
Vendor Advisory
https://github.com/torvalds/linux/commit/6cd88243c7e03845a450795e134b488fc2afb736
Patch
Third Party Advisory
https://lists.debian.org/debian-lts-announce/2023/10/msg00027.html
https://security.netapp.com/advisory/ntap-20230214-0007/
Third Party Advisory
https://www.debian.org/security/2023/dsa-5480
Third Party Advisory
VDB Entry