CVE-2022-39189: Use After Free
A flaw was found in the x86 KVM subsystem in kvmstealtimesetpreempted in arch/x86/kvm/x86.c in the Linux kernel. Unprivileged guest users can compromise the guest kernel because TLB flush operations are mishandled in certain KVMVCPUPREEMPTED situations.
Other sources
An issue was discovered the x86 KVM subsystem in the Linux kernel before 5.18.17. Unprivileged guest users can compromise the guest kernel because TLB flush operations are mishandled in certain KVMVCPUPREEMPTED situations.
Affected Software
Remediation
Information
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2022-39189?
CVE-2022-39189 has a high severity rating due to its potential to allow unprivileged guest users to compromise the guest kernel.
How do I fix CVE-2022-39189?
To fix CVE-2022-39189, update to the recommended kernel versions specified in the remediation section.
What systems are affected by CVE-2022-39189?
CVE-2022-39189 impacts various versions of the Linux kernel and specific NetApp HCI baseboard management controllers.
Can CVE-2022-39189 be exploited remotely?
CVE-2022-39189 does not appear to be a remotely exploitable vulnerability, as it involves unprivileged access within guest environments.
Is there a workaround for CVE-2022-39189?
Currently, there are no known workarounds for CVE-2022-39189 other than applying the appropriate updates.