Back

MEDIUM

kernel: KVM: x86/mmu: race condition in direct_page_fault()

Published Nov 30, 2022

Description

A race condition in the x86 KVM subsystem in the Linux kernel through 6.1-rc6 allows guest OS users to cause a denial of service (host OS crash or host OS memory corruption) when nested virtualisation and the TDP MMU are enabled.

Affected products

Remediation

Red Hat statement

The nested virtualization feature is not enabled by default up to Red Hat Enterprise Linux 8.4. Most importantly, Red Hat currently provides nested virtualization only as a Technology Preview and is therefore unsupported for production use. For additional details, please see https://access.redhat.com/solutions/21101 and https://access.redhat.com/support/offerings/techpreview.

Red Hat mitigation

This vulnerability can be mitigated by disabling the nested virtualization feature. For Intel: ``` # modprobe -r kvm_intel # modprobe kvm_intel nested=0 ``` For AMD: ``` # modprobe -r kvm_amd # modprobe kvm_amd nested=0 ```

Weaknesses (1)

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Nov 30, 2022
Updated Apr 24, 2025
Reserved Nov 23, 2022
CISA Vulnrichment
Updated Apr 24, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Nov 23, 2022
ENISA EUVD
Assigner mitre
Published Nov 30, 2022
Updated Apr 24, 2025
Exploited since n/a
EUVD-2022-48721