PT-2025-8492 · Linux+4 · Linux Kernel+4

Paolo Bonzini

+1

·

Published

2022-04-13

·

Updated

2025-09-29

·

CVE-2022-49559

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.17.0-rc3+
Description A vulnerability in the Linux kernel has been identified, specifically in the KVM (Kernel-based Virtual Machine) component for x86 architecture. The issue arises from the handling of triple faults in L2 (nested virtualization) and how userspace can induce KVM REQ TRIPLE FAULT without going through KVM RUN, which guarantees the handling of the triple fault by kvm check nested state(). This can be triggered if userspace injects a machine check while L2 is active and CR4.MCE=0. The vulnerability does not specify the number of potentially affected devices or details about real-world incidents.
Recommendations For Linux kernel versions prior to 5.17.0-rc3+, update to a version that includes the fix for the KVM x86 triple fault handling issue. As a temporary workaround, consider restricting the use of nested virtualization until a patch is available.

Exploit

Fix

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
BDU:2026-04023
CESA-2022_7683
CVE-2022-49559
RHSA-2022:7683
RHSA-2022:8267
RHSA-2022_7683
RHSA-2022_8267
SUSE-SU-2025:1027-1
SUSE-SU-2025:1176-1
SUSE-SU-2025:1183-1
SUSE-SU-2025:1241-1
SUSE-SU-2025_1027-1
SUSE-SU-2025_1241-1

Affected Products

Astra Linux
Centos
Linux Kernel
Red Hat
Suse