PT-2025-26154 · Linux+6 · Linux Kernel+6

Published

2023-05-09

·

Updated

2025-10-14

·

CVE-2022-50228

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.17.0-rc3+
Description A vulnerability in the Linux kernel has been resolved, specifically in the KVM: SVM component. The issue occurs when userspace injects an interrupt with GIF=0, which can cause the kernel to BUG or WARN. This situation can be forced by userspace via KVM SET VCPU EVENTS. The vulnerability is related to the svm inject irq function and can be triggered by injecting pending events through the inject pending event function, which is called by kvm arch vcpu ioctl run and kvm vcpu ioctl. The estimated number of potentially affected devices is not provided.
Recommendations To resolve the issue, update the Linux kernel to a version later than 5.17.0-rc3+. As a temporary workaround, consider restricting access to the KVM SET VCPU EVENTS interface to minimize the risk of exploitation. Avoid using the svm inject irq function until the issue is resolved. At the moment, there is no information about additional mitigation measures.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

ALSA-2025:17797
ALSA-2025:17812
ALSA-2025_16880
ALSA-2025_17797
ALSA-2025_17812
CESA-2025_17797
CESA-2025_17812
CVE-2022-50228
INFSA-2025_17797
INFSA-2025_17812
OESA-2025-1820
RHSA-2023:2458
RHSA-2023_2458
RHSA-2025:17797
RHSA-2025:17812
RHSA-2025:18932
RHSA-2025:19222
RHSA-2025_17797
RHSA-2025_17812
SUSE-SU-2025:02264-1
SUSE-SU-2025:02321-1
SUSE-SU-2025:02322-1
SUSE-SU-2025:02537-1
SUSE-SU-2025:03204-1
SUSE-SU-2025:2264-1
SUSE-SU-2025_02264-1
SUSE-SU-2025_02537-1
SUSE-SU-2025_03204-1

Affected Products

Almalinux
Astra Linux
Centos
Linux Kernel
Red Hat
Rocky Linux
Suse