PT-2022-7516 · Linux+5 · Linux Kernel+5

Published

2022-01-26

·

Updated

2026-03-14

·

CVE-2022-48765

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.17.0-rc1+ #5
Description The issue is related to the Kernel-based Virtual Machine (KVM) component in the Linux kernel. It can be triggered by not exposing tsc-deadline mode and doing a reboot in the guest system. The lapic shutdown() function, which is called during the sys reboot path, does not disarm the flying timer; it only masks LVTT. This can lead to a timer-mode switch between tsc-deadline and oneshot/periodic modes, resulting in the preemption timer being cancelled in apic update lvtt(). The vulnerability can cause a denial of service.
Recommendations To resolve the issue, update the Linux kernel to a version that includes the fix for this vulnerability. Specifically, for versions prior to 5.17.0-rc1+ #5, update to a newer version that includes the patch for KVM: LAPIC: Also cancel preemption timer during SET LAPIC.
As a temporary workaround, consider disabling the lapic shutdown() function or restricting the use of the KVM component until a patch is available. However, this may have significant performance implications and should be carefully evaluated before implementation.
At the moment, there is no information about other workarounds or configuration changes that can mitigate this issue without updating the kernel.

Exploit

Fix

Improper Resource Release

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
BDU:2024-06800
CESA-2022_7683
CVE-2022-48765
OESA-2024-1838
OESA-2024-1839
OPENSUSE-SU-2024_2372-1
OPENSUSE-SU-2024_2394-1
RHSA-2022:7683
RHSA-2022:8267
RHSA-2022_7683
RHSA-2022_8267
SUSE-SU-2024:2372-1
SUSE-SU-2024:2394-1
SUSE-SU-2024:2902-1
SUSE-SU-2024:2929-1
SUSE-SU-2024:2939-1

Affected Products

Centos
Debian
Linux Kernel
Red Hat
Red Os
Suse