Back

HIGH

kernel: missing check in ioctl allows kernel memory read/write

Published Mar 8, 2022

Description

A vulnerability was found in kvm_s390_guest_sida_op in the arch/s390/kvm/kvm-s390.c function in KVM for s390 in the Linux kernel. This flaw allows a local attacker with a normal user privilege to obtain unauthorized memory write access. This flaw affects Linux kernel versions prior to 5.17-rc4.

Affected products

Remediation

Red Hat mitigation

As the kvm.ko kernel module will be auto-loaded when required, its use can be disabled by preventing the module from loading with the following instructions: # echo "install kvm /bin/true" >> /etc/modprobe.d/disable-kvm.conf If the system requires this module to work correctly, this mitigation may not be suitable. If you need further assistance, see the KCS article https://access.redhat.com/solutions/41278 or contact Red Hat Global Support Services.

Metrics

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Mar 8, 2022
Updated Aug 2, 2024
Reserved Feb 7, 2022
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Feb 9, 2022