CVE-2022-1158

CVSS v3.1 7.8 (High)
78% Progress
EPSS 0.04 % (5th)
0.04% Progress
Affected Products 3
Advisories 30

A flaw was found in KVM. When updating a guest's page table entry, vm_pgoff was improperly used as the offset to get the page's pfn. As vaddr and vm_pgoff are controllable by user-mode processes, this flaw allows unprivileged local users on the host to write outside the userspace region and potentially corrupt the kernel, resulting in a denial of service condition.

Weaknesses
CWE-416
Use After Free
CVE Status
PUBLISHED
CNA
Red Hat, Inc.
Published Date
2022-08-05 17:15:08
(2 years ago)
Updated Date
2023-04-11 18:14:00
(17 months ago)

Affected Products

Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Linux Kernel from 5.2 version and prior 5.4.189 version cpe:2.3:o:linux:linux_kernel >= 5.2 < 5.4.189
  Linux Kernel from 5.5 version and prior 5.10.110 version cpe:2.3:o:linux:linux_kernel >= 5.5 < 5.10.110
  Linux Kernel from 5.11 version and prior 5.15.33 version cpe:2.3:o:linux:linux_kernel >= 5.11 < 5.15.33
  Linux Kernel from 5.16 version and prior 5.16.19 version cpe:2.3:o:linux:linux_kernel >= 5.16 < 5.16.19
  Linux Kernel from 5.17 version and prior 5.17.2 version cpe:2.3:o:linux:linux_kernel >= 5.17 < 5.17.2

Configuration #2

    CPE23 From Up To
  Fedoraproject Fedora 36 cpe:2.3:o:fedoraproject:fedora:36

Configuration #3

    CPE23 From Up To
  Redhat Enterprise Linux 8.0 cpe:2.3:o:redhat:enterprise_linux:8.0
  Redhat Enterprise Linux 9.0 cpe:2.3:o:redhat:enterprise_linux:9.0
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...