CVE-2022-1158
Summary
| CVE | CVE-2022-1158 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-08-05 17:15:00 UTC |
| Updated | 2023-04-11 18:14:00 UTC |
| Description | A flaw was found in KVM. When updating a guest's page table entry, vm_pgoff was improperly used as the offset to get the page's pfn. As vaddr and vm_pgoff are controllable by user-mode processes, this flaw allows unprivileged local users on the host to write outside the userspace region and potentially corrupt the kernel, resulting in a denial of service condition. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| August 2022 Linux Kernel 5.17 Vulnerabilities in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
|
| 2069793 – (CVE-2022-1158) CVE-2022-1158 kernel: KVM: cmpxchg_gpte can write to pfns outside the userspace region |
MISC |
bugzilla.redhat.com |
|
| oss-security - CVE-2022-1158: Linux Kernel v5.2+: x86/kvm: cmpxchg_gpte can write to
pfns outside the userspace region |
MISC |
www.openwall.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159745 Oracle Enterprise Linux Security Update for unbreakable enterprise kernel-container (ELSA-2022-9265)
- 159746 Oracle Enterprise Linux Security Update for unbreakable enterprise kernel (ELSA-2022-9264)
- 159754 Oracle Enterprise Linux Security Update for unbreakable enterprise kernel-container (ELSA-2022-9274)
- 159755 Oracle Enterprise Linux Security Update for unbreakable enterprise kernel (ELSA-2022-9273)
- 159785 Oracle Enterprise Linux Security Update for unbreakable enterprise kernel-container (ELSA-2022-9368)
- 159788 Oracle Enterprise Linux Security Update for unbreakable enterprise kernel (ELSA-2022-9365)
- 179258 Debian Security Update for linux (DSA 5127-1)
- 184453 Debian Security Update for linux (CVE-2022-1158)
- 198783 Ubuntu Security Notification for Linux kernel (OEM) Vulnerabilities (USN-5416-1)
- 198822 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-5469-1)
- 198824 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-5467-1)
- 198826 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-5468-1)
- 240953 Red Hat Update for kernel (RHSA-2022:8685)
- 240954 Red Hat Update for kernel-rt (RHSA-2022:8673)
- 240956 Red Hat Update for kpatch-patch (RHSA-2022:8686)
- 240968 Red Hat Update for kernel (RHSA-2022:8809)
- 240969 Red Hat Update for kpatch-patch (RHSA-2022:8831)
- 241003 Red Hat Update for kernel-rt (RHSA-2022:8941)
- 241008 Red Hat Update for kernel (RHSA-2022:8973)
- 241009 Red Hat Update for kernel-rt (RHSA-2022:8974)
- 241022 Red Hat Update for kpatch-patch (RHSA-2022:9082)
- 353964 Amazon Linux Security Advisory for kernel : ALAS2KERNEL-5.15-2022-001
- 354327 Amazon Linux Security Advisory for kernel : ALAS2022-2022-083
- 354468 Amazon Linux Security Advisory for kernel : ALAS2022-2022-185
- 354542 Amazon Linux Security Advisory for kernel : ALAS-2022-185
- 355199 Amazon Linux Security Advisory for kernel : ALAS2023-2023-070
- 355563 Amazon Linux Security Advisory for kernel : ALAS2KERNEL-5.10-2023-036
- 355565 Amazon Linux Security Advisory for kernel : ALAS2KERNEL-5.15-2023-023
- 376925 Alibaba Cloud Linux Security Update for cloud-kernel (ALINUX3-SA-2022:0125)
- 6140399 AWS Bottlerocket Security Update for kernel (GHSA-hjwr-px7g-4988)
- 752126 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:1687-1)
- 752242 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:2104-1)
- 753100 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 15 for SLE 15 SP2) (SUSE-SU-2022:1605-1)
- 753152 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 17 for SLE 15 SP3) (SUSE-SU-2022:1573-1)
- 753176 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:1676-1)
- 753224 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 24 for SLE 15 SP2) (SUSE-SU-2022:1629-1)
- 753227 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 12 for SLE 15 SP3) (SUSE-SU-2022:1569-1)
- 753241 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 10 for SLE 15 SP3) (SUSE-SU-2022:1575-1)
- 753256 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 13 for SLE 15 SP2) (SUSE-SU-2022:1591-1)
- 753260 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 16 for SLE 15 SP3) (SUSE-SU-2022:1571-1)
- 753299 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:1669-1)
- 753349 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 23 for SLE 15 SP2) (SUSE-SU-2022:1637-1)
- 753453 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 26 for SLE 15 SP2) (SUSE-SU-2022:1634-1)
- 902726 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (10522)
- 902743 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (10540)
- 903990 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (10522-1)
- 904150 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (10540-1)
- 905958 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (10522-2)
- 906497 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (10540-2)