CVE-2023-5090: Kernel: kvm: svm: improper check in svm_set_x2apic_msr_interception allows direct access to host x2apic msrs
A flaw was found in KVM. An improper check in svmsetx2apicmsrinterception() may allow direct access to host x2apic msrs when the guest resets its apic, potentially leading to a denial of service condition.
Other sources
An improper check in svmsetx2apicmsrinterception() may allow direct access to host x2apic msrs when the guest resets its apic, potentially leading to a denial of service condition.
Upstream patch & commit: https://lore.kernel.org/kvm/20230928173354.217464-1-mlevitsk@redhat.com/T https://github.com/torvalds/linux/commit/b65235f6e102354ccafda601eaa1c5bef5284d21
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.22-1Fixed in 6.12.25-1 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 6.6 - Upgrade
Upgrade
Linux Kernel (KVM)to a version that resolves this vulnerability.Patch b65235f6e102354ccafda601eaa1c5bef5284d21 - Compensating control
Mitigate the risk of guest-triggered host x2APIC MSR access until the upstream KVM fix is applied by isolating or restricting access to untrusted guests/workloads (e.g., run in a more isolated environment or limit which guests can reset APIC).
Event History
Frequently Asked Questions
What is CVE-2023-5090?
CVE-2023-5090 is a vulnerability in KVM that allows direct access to host x2apic msrs, potentially leading to a denial of service condition.
What is the severity of CVE-2023-5090?
The severity of CVE-2023-5090 is medium with a severity value of 6.
How does CVE-2023-5090 affect the kernel?
CVE-2023-5090 affects the kernel by allowing improper access to host x2apic msrs, which could lead to a denial of service.
How can I fix CVE-2023-5090?
To fix CVE-2023-5090, update the affected kernel to version 6.6 or higher.
Where can I find more information about CVE-2023-5090?
You can find more information about CVE-2023-5090 at the following references: [Reference 1](https://access.redhat.com/security/cve/CVE-2023-5090), [Reference 2](https://bugzilla.redhat.com/show_bug.cgi?id=2248122), [Reference 3](https://lore.kernel.org/kvm/20230928173354.217464-1-mlevitsk@redhat.com/T)