Back

MEDIUM

kernel: KVM: SVM: nested shutdown interception could lead to host crash

Published Oct 24, 2022

Description

A flaw was found in the KVM's AMD nested virtualization (SVM). A malicious L1 guest could purposely fail to intercept the shutdown of a cooperative nested guest (L2), possibly leading to a page fault and kernel panic in the host (L0).

Affected products

Remediation

Red Hat statement

Red Hat currently provides the nested virtualization feature as a Technology Preview. Nested virtualization is therefore unsupported for production use. For more information please refer to https://access.redhat.com/solutions/21101 and https://access.redhat.com/support/offerings/techpreview.

Red Hat mitigation

This vulnerability can be mitigated by disabling the nested virtualization feature: ``` # modprobe -r kvm_amd # modprobe kvm_amd nested=0 ```

Weaknesses (1)

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Oct 24, 2022
Updated May 7, 2025
Reserved Sep 27, 2022
CISA Vulnrichment
Updated May 7, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Oct 20, 2022
ENISA EUVD
Assigner redhat
Published Oct 24, 2022
Updated May 7, 2025
Exploited since n/a
EUVD-2022-42731