kernel: KVM: x86/mmu: race condition in direct_page_fault()
Published Nov 30, 2022
5.5
MEDIUMCVSS 3.1
EPSS 0.25%
Description
A race condition in the x86 KVM subsystem in the Linux kernel through 6.1-rc6 allows guest OS users to cause a denial of service (host OS crash or host OS memory corruption) when nested virtualisation and the TDP MMU are enabled.
Affected products
No data.
- < 6.1
- 6.1
- 6.1
- 6.1
- 6.1
- 6.1
- 6.1
No data.
Red Hat Enterprise Linux 8
kernel-0:4.18.0-513.5.1.el8_9
Fixed · RHSA-2023:7077
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-513.5.1.rt7.307.el8_9
Fixed · RHSA-2023:6901
Red Hat Enterprise Linux 8.6 Extended Update Support
kernel-0:4.18.0-372.95.1.el8_6
Fixed · RHSA-2024:1188
Red Hat Enterprise Linux 8.8 Extended Update Support
kernel-0:4.18.0-477.51.1.el8_8
Fixed · RHSA-2024:1404
Red Hat Enterprise Linux 9
kernel-0:5.14.0-284.25.1.el9_2
Fixed · RHSA-2023:4377
Red Hat Enterprise Linux 9
kernel-0:5.14.0-284.25.1.el9_2
Fixed · RHSA-2023:4377
Red Hat Enterprise Linux 9
kernel-rt-0:5.14.0-284.25.1.rt14.310.el9_2
Fixed · RHSA-2023:4378
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8
kernel-0:4.18.0-372.95.1.el8_6
Fixed · RHSA-2024:1188
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-513.5.1.el8_9 | Fixed | RHSA-2023:7077 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-513.5.1.rt7.307.el8_9 | Fixed | RHSA-2023:6901 |
| Red Hat Enterprise Linux 8.6 Extended Update Support | kernel-0:4.18.0-372.95.1.el8_6 | Fixed | RHSA-2024:1188 |
| Red Hat Enterprise Linux 8.8 Extended Update Support | kernel-0:4.18.0-477.51.1.el8_8 | Fixed | RHSA-2024:1404 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-284.25.1.el9_2 | Fixed | RHSA-2023:4377 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-284.25.1.el9_2 | Fixed | RHSA-2023:4377 |
| Red Hat Enterprise Linux 9 | kernel-rt-0:5.14.0-284.25.1.rt14.310.el9_2 | Fixed | RHSA-2023:4378 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 | kernel-0:4.18.0-372.95.1.el8_6 | Fixed | RHSA-2024:1188 |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
The nested virtualization feature is not enabled by default up to Red Hat Enterprise Linux 8.4. Most importantly, Red Hat currently provides nested virtualization only as a Technology Preview and is therefore unsupported for production use. For additional details, please see https://access.redhat.com/solutions/21101 and https://access.redhat.com/support/offerings/techpreview.
Red Hat mitigation
This vulnerability can be mitigated by disabling the nested virtualization feature. For Intel: ``` # modprobe -r kvm_intel # modprobe kvm_intel nested=0 ``` For AMD: ``` # modprobe -r kvm_amd # modprobe kvm_amd nested=0 ```
References (6)
- https://access.redhat.com/security/cve/CVE-2022-45869 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2151317 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-48721 Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=47b0c2e4c220f2251fd8dcfbb44479819c715e15 ExploitPatchVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-45869
- https://www.cve.org/CVERecord?id=CVE-2022-45869
Change history (0)
No recorded changes yet.