kernel: KVM: NULL pointer dereference in kvm_irq_delivery_to_apic_fast()
Published Aug 31, 2022
5.5
MEDIUMCVSS 3.1
EPSS 0.47%
Description
A flaw was found in the Linux kernel’s KVM when attempting to set a SynIC IRQ. This issue makes it possible for a misbehaving VMM to write to SYNIC/STIMER MSRs, causing a NULL pointer dereference. This flaw allows an unprivileged local attacker on the host to issue specific ioctl calls, causing a kernel oops condition that results in a denial of service.
Affected products
- Vendor n/a Product Kernel Defaultn/a
- Version kernel 5.18StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Kernel | n/a |
|
Configuration 1
- < 5.18
Configuration 2
- 36
Configuration 3
- 6.0
- 7.0
- 8.0
- 9.0
Configuration 4
- 10.0
No data.
Red Hat Enterprise Linux 8
kernel-0:4.18.0-425.3.1.el8
Fixed · RHSA-2022:7683
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-425.3.1.rt7.213.el8
Fixed · RHSA-2022:7444
Red Hat Enterprise Linux 9
kernel-0:5.14.0-162.6.1.el9_1
Fixed · RHSA-2022:8267
Red Hat Enterprise Linux 9
kernel-0:5.14.0-162.6.1.el9_1
Fixed · RHSA-2022:8267
Red Hat Enterprise Linux 9
kernel-rt-0:5.14.0-162.6.1.rt21.168.el9_1
Fixed · RHSA-2022:7933
Red Hat Enterprise Linux 6
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel-rt
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-425.3.1.el8 | Fixed | RHSA-2022:7683 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-425.3.1.rt7.213.el8 | Fixed | RHSA-2022:7444 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-162.6.1.el9_1 | Fixed | RHSA-2022:8267 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-162.6.1.el9_1 | Fixed | RHSA-2022:8267 |
| Red Hat Enterprise Linux 9 | kernel-rt-0:5.14.0-162.6.1.rt21.168.el9_1 | Fixed | RHSA-2022:7933 |
| Red Hat Enterprise Linux 6 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (8 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 0.47% (0.00466) | 38.10th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.44% (0.00443) | 35.07th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.02% (0.00023) | 3.52th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.04% (0.00042) | 5.07th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.04% (0.00042) | 5.63th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.03% (0.01034) | 41.69th | v2 (v2022.01.01) |
| Oct 3, 2022 | 1.03% (0.01034) | 40.14th | v2 (v2022.01.01) |
| Sep 1, 2022 | 0.95% (0.00950) | 30.52th | v2 (v2022.01.01) |
References (10)
- https://access.redhat.com/security/cve/CVE-2022-2153 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2069736 Issue TrackingPatchThird Party Advisory
- https://github.com/torvalds/linux/commit/00b5f37189d24ac3ed46cb7f11742094778c46ce PatchThird Party Advisory
- https://github.com/torvalds/linux/commit/7ec37d1cbe17d8189d9562178d8b29167fe1c31a PatchThird Party Advisory
- https://github.com/torvalds/linux/commit/b1e34d325397a33d97d845e312d7cf2a8b646b44 PatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/10/msg00000.html mailing-listMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/11/msg00001.html mailing-listMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-2153
- https://www.cve.org/CVERecord?id=CVE-2022-2153
- https://www.openwall.com/lists/oss-security/2022/06/22/1 ExploitMailing ListPatchThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-2153 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2069736 | Issue TrackingPatchThird Party Advisory | |
| https://github.com/torvalds/linux/commit/00b5f37189d24ac3ed46cb7f11742094778c46ce | PatchThird Party Advisory | |
| https://github.com/torvalds/linux/commit/7ec37d1cbe17d8189d9562178d8b29167fe1c31a | PatchThird Party Advisory | |
| https://github.com/torvalds/linux/commit/b1e34d325397a33d97d845e312d7cf2a8b646b44 | PatchThird Party Advisory | |
| https://lists.debian.org/debian-lts-announce/2022/10/msg00000.html | mailing-listMailing ListThird Party Advisory | |
| https://lists.debian.org/debian-lts-announce/2022/11/msg00001.html | mailing-listMailing ListThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-2153 | ||
| https://www.cve.org/CVERecord?id=CVE-2022-2153 | ||
| https://www.openwall.com/lists/oss-security/2022/06/22/1 | ExploitMailing ListPatchThird Party Advisory |
Change history (0)
No recorded changes yet.