CVE-2022-2196

Summary

A regression exists in the Linux Kernel within KVM: nVMX that allowed for speculative execution attacks. L2 can carry out Spectre v2 attacks on L1 due to L1 thinking it doesn't need retpolines or IBPB after running L2 due to KVM (L0) advertising eIBRS support to L1. An attacker at L2 with code execution can execute code on an indirect branch on the host machine. We recommend upgrading to Kernel 6.2 or applying the relevant stable backports (v5.4.233, v5.10.170, v5.15.96, v6.1.14).

Affected Software

VendorProductVersion RangeStatus
LinuxLinux Kernel64b8f33b2e1e687d465b5cb382e7bec495f1e026 < f93a1a5bdcdd122aae0a3eab7a52c15b71fb725baffected
LinuxLinux Kernele089a83fbc55b8057f332c00f125acaa02b08ef7 < 2e7eab81425ad6c875f2ed47c0ce01e78afc38a5affected
LinuxLinux Kernel02a3868d18fe639363f1cea6e6d7914513198e43 < 2e7eab81425ad6c875f2ed47c0ce01e78afc38a5affected
LinuxLinux Kernel5c911beff20aa8639e7a1f28988736c13e03ed54 < 1b0cafaae8884726c597caded50af185ffc13349affected
LinuxLinux Kernel5c911beff20aa8639e7a1f28988736c13e03ed54 < 6b539a7dbb49250f92515c2ba60aea239efc9e35affected
LinuxLinux Kernel5c911beff20aa8639e7a1f28988736c13e03ed54 < 63fada296062e91ad9f871970d4e7f19e21a6a15affected
LinuxLinux Kernel5c911beff20aa8639e7a1f28988736c13e03ed54 < 2e7eab81425ad6c875f2ed47c0ce01e78afc38a5affected
LinuxLinux Kernel5.4.47 < 5.4.233affected
LinuxLinux Kernel5.6.19 < 5.7.0affected
LinuxLinux Kernel5.7.3 < 5.8.0affected
LinuxLinux Kernel5.8.0 < 5.10.170affected
LinuxLinux Kernel5.11.0 < 5.15.96affected
LinuxLinux Kernel5.16.0 < 6.1.14affected
LinuxLinux Kernel6.2.0unaffected

Weaknesses

  • CWE-1188: CWE-1188 Insecure Default Initialization of Resource

ADP Enrichment

CVE Program Container

Additional References

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References