PT-2022-5550 · Linux+8 · Linux Kernel+8

Gaoning Pan

+2

·

Published

2020-08-26

·

Updated

2023-05-16

·

CVE-2022-1789

CVSS v2.0

6.9

Medium

VectorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to pointer dereference errors in the Linux kernel. It allows an attacker to access confidential data, compromise its integrity, and cause a denial of service. Specifically, with shadow paging enabled, the INVPCID instruction results in a call to kvm mmu invpcid gva. If INVPCID is executed with CR0.PG=0, the invlpg callback is not set, leading to a NULL pointer dereference.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2023:2148
ALSA-2023:2458
ALSA-2023:2736
ALSA-2023:2951
ALT-PU-2020-2688
ALT-PU-2020-2716
ALT-PU-2020-2770
ALT-PU-2020-3210
ALT-PU-2021-1083
ALT-PU-2021-1105
ALT-PU-2021-1621
ALT-PU-2021-1656
ALT-PU-2021-1739
ALT-PU-2021-1862
ALT-PU-2021-1866
ALT-PU-2021-1870
ALT-PU-2022-2052
ALT-PU-2022-2054
ALT-PU-2022-2158
BDU:2022-06902
CESA-2023_2736
CESA-2023_2951
CVE-2022-1789
DSA-5161-1
MGASA-2022-0212
MGASA-2022-0230
OESA-2022-1705
OPENSUSE-SU-2022_2520-1
OPENSUSE-SU-2022_2615-1
RHSA-2023:2148
RHSA-2023:2458
RHSA-2023:2736
RHSA-2023:2951
RHSA-2023_2148
RHSA-2023_2458
RHSA-2023_2736
RHSA-2023_2951
RHSA-2024:4447
SUSE-SU-2022:2520-1
SUSE-SU-2022:2615-1
USN-5514-1
USN-5518-1
USN-5529-1
USN-5539-1
USN-5564-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Linux Kernel
Red Hat
Suse
Ubuntu