UBUNTU-CVE-2022-1789
Dashboard / Vulnerabilities / UBUNTU-CVE-2022-1789
UBUNTU-CVE-2022-1789
Summary:
Details: With shadow paging enabled, the INVPCID instruction results in a call to kvm_mmu_invpcid_gva. If INVPCID is executed with CR0.PG=0, the invlpg callback is not set and the result is a NULL pointer dereference.
References: https://ubuntu.com/security/CVE-2022-1789, https://git.kernel.org/linus/9f46c187e2e680ecd9de7983e4d081c3391acc76, https://www.openwall.com/lists/oss-security/2022/05/25/2, https://ubuntu.com/security/notices/USN-5514-1, https://ubuntu.com/security/notices/USN-5529-1, https://ubuntu.com/security/notices/USN-5518-1, https://ubuntu.com/security/notices/USN-5539-1, https://ubuntu.com/security/notices/USN-5564-1, https://www.cve.org/CVERecord?id=CVE-2022-1789
Affected packages
Package
Name: linux-hwe-edge
Purl: pkg:deb/ubuntu/linux-hwe-edge?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
