CVE-2022-2196
Last modified
CVE-2022-2196 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. A regression exists in the Linux Kernel within KVM: nVMX that allowed for speculative execution attacks. L2 can carry out Spectre v2 attacks on L1 due to L1 thinking it doesn't need retpolines or IBPB after running L2 due to KVM (L0) advertising eIBRS support to L1. An attacker at L2 with code execution can execute code on an indirect branch on the host machine. EPSS estimates a 0.29% chance of exploitation in the next 30 days.
Description
A regression exists in the Linux Kernel within KVM: nVMX that allowed for speculative execution attacks. L2 can carry out Spectre v2 attacks on L1 due to L1 thinking it doesn't need retpolines or IBPB after running L2 due to KVM (L0) advertising eIBRS support to L1. An attacker at L2 with code execution can execute code on an indirect branch on the host machine. We recommend upgrading to Kernel 6.2 or past commit 2e7eab81425a
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 5.4.47, < 5.4.233 |
| Linux | Linux Kernel | >= 5.6.19, < 5.7 |
| Linux | Linux Kernel | >= 5.7.3, < 5.10.170 |
| Linux | Linux Kernel | >= 5.11, < 5.15.96 |
| Linux | Linux Kernel | >= 5.16, < 6.1.14 |
| Debian | Debian Linux | 10.0 |
References
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=2e7eab81425ad6c875f2ed47c0ce01e78afc38a5Mailing List, Patch, Vendor Advisory
- https://kernel.dance/#2e7eab81425aPatch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/05/msg00005.htmlMailing List, Third Party Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=2e7eab81425ad6c875f2ed47c0ce01e78afc38a5Mailing List, Patch, Vendor Advisory
- https://kernel.dance/#2e7eab81425aPatch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/05/msg00005.htmlMailing List, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-2196?
How severe is CVE-2022-2196?
How do I fix CVE-2022-2196?
Are you affected by CVE-2022-2196?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
