Database/Kernel, userspace & hypervisor

KVM: NULL pointer dereference in kvm_irq_delivery_to_apic_fast() - guest crashes the host
CVSS 5.5CVE-2022-2153Kernel, userspace & hypervisorcurated
Impact
NULL pointer dereference in kvm_irq_delivery_to_apic_fast() - guest crashes the host
Who can reach it
Tenant VM guest
What to do
Kernel patch; KVM-module scope usually forces drain + reboot rather than livepatch
References
Related entries
- KVM: Improper handling of VM_IO/VM_PFNMAP vmas in KVM lets a guest bypass read-only checksCVE-2021-22543 · KVMHigh
- Linux kernel (mm anon_vma): Use-after-free from leaf anon_vma double reuse - memory corruption / privesc primitiveCVE-2022-42703 · Linux kernel (mm anon_vma)Medium
- Linux kernel (KASLR): EntryBleed: prefetch side channel defeats KASLR even with KPTICVE-2022-4543 · Linux kernel (KASLR)Medium
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): A NULL pointer dereference in the amdkfd (KFD computeCVE-2022-49055 · Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd)Medium
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): A race condition or locking defect in the amdkfd (KFDCVE-2022-49133 · Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd)Medium
- Linux kernel (drivers/vfio/pci): Whoever holds the VFIO device fd for a passed-through PCI function can make the hostCVE-2022-49219 · Linux kernel (drivers/vfio/pci)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.