CVE-2022-0171: Medium severity Linux Linux kernel vulnerability
A flaw was found in the Linux kernel. The existing KVM SEV API has a vulnerability that allows a non-root (host) user-level application to crash the host kernel by creating a confidential guest VM instance in AMD CPU that supports Secure Encrypted Virtualization (SEV).
Other sources
The existing KVM SEV API has a vulnerability that allows a non-root (host) user-level application to crash the host kernel by creating a confidential guest VM instance in AMD CPU that supports SEV.
Upstream fix:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=bb4ce2c65881a2b9bdcd384f54a260a12a89dd91
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2022-0171?
CVE-2022-0171 is a high-severity vulnerability that could allow a non-root user-level application to crash the host kernel.
How do I fix CVE-2022-0171?
To fix CVE-2022-0171, users should update their Linux kernel to version 5.18 or later.
Which Linux distributions are affected by CVE-2022-0171?
CVE-2022-0171 affects Red Hat Enterprise Linux and Debian-based distributions with specific kernel versions listed.
Can CVE-2022-0171 impact virtualization security?
Yes, CVE-2022-0171 poses a risk to virtualization security as it affects the KVM SEV API used in AMD CPUs.
Is there a workaround for CVE-2022-0171?
There are currently no documented workarounds for CVE-2022-0171; the best approach is to apply the kernel update promptly.