CVE-2022-2196
Last modified
CVE-2022-2196 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. A regression exists in the Linux Kernel within KVM: nVMX that allowed for speculative execution attacks. L2 can carry out Spectre v2 attacks on L1 due to L1 thinking it doesn't need retpolines or IBPB after running L2 due to KVM (L0) advertising eIBRS support to L1. An attacker at L2 with code execution can execute code on an indirect branch on the host machine. EPSS estimates a 0.29% chance of exploitation in the next 30 days.
Description
A regression exists in the Linux Kernel within KVM: nVMX that allowed for speculative execution attacks. L2 can carry out Spectre v2 attacks on L1 due to L1 thinking it doesn't need retpolines or IBPB after running L2 due to KVM (L0) advertising eIBRS support to L1. An attacker at L2 with code execution can execute code on an indirect branch on the host machine. We recommend upgrading to Kernel 6.2 or applying the relevant stable backports (v5.4.233, v5.10.170, v5.15.96, v6.1.14).
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 5.4.47, < 5.4.233 |
| Linux | Linux Kernel | >= 5.6.19, < 5.7 |
| Linux | Linux Kernel | >= 5.7.3, < 5.10.170 |
| Linux | Linux Kernel | >= 5.11, < 5.15.96 |
| Linux | Linux Kernel | >= 5.16, < 6.1.14 |
| Debian | Debian Linux | 10.0 |
References
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=2e7eab81425ad6c875f2ed47c0ce01e78afc38a5Mailing List, Patch, Vendor Advisory
- https://kernel.dance/#2e7eab81425aPatch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/05/msg00005.htmlMailing List, Third Party Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=2e7eab81425ad6c875f2ed47c0ce01e78afc38a5Mailing List, Patch, Vendor Advisory
- https://kernel.dance/#2e7eab81425aPatch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/05/msg00005.htmlMailing List, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-2196?
How severe is CVE-2022-2196?
How do I fix CVE-2022-2196?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-21952A Missing Authentication for Critical Function vulnerability…7.5
- CVE-2022-21953A Missing Authorization vulnerability in of SUSE Rancher all…8.8
- CVE-2022-21954Microsoft Edge (Chromium-based) Elevation of Privilege Vulne…6.1
- CVE-2022-21957Microsoft Dynamics 365 On-Premises Remote Code Execution Vul…7.2
- CVE-2022-21958Windows Resilient File System (ReFS) Remote Code Execution V…6.8
- CVE-2022-21959Windows Resilient File System (ReFS) Remote Code Execution V…6.8
- CVE-2022-21960Windows Resilient File System (ReFS) Remote Code Execution V…6.8
- CVE-2022-21961Windows Resilient File System (ReFS) Remote Code Execution V…6.8
- CVE-2022-21962Windows Resilient File System (ReFS) Remote Code Execution V…6.8
- CVE-2022-21963Windows Resilient File System (ReFS) Remote Code Execution V…6.8
- CVE-2022-21964Remote Desktop Licensing Diagnoser Information Disclosure Vu…5.5
- CVE-2022-21965Microsoft Teams Denial of Service Vulnerability7.5
Are you affected by CVE-2022-2196?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
