UBUNTU-CVE-2022-2153
Dashboard / Vulnerabilities / UBUNTU-CVE-2022-2153
UBUNTU-CVE-2022-2153
Summary:
Details: A flaw was found in the Linux kernel’s KVM when attempting to set a SynIC IRQ. This issue makes it possible for a misbehaving VMM to write to SYNIC/STIMER MSRs, causing a NULL pointer dereference. This flaw allows an unprivileged local attacker on the host to issue specific ioctl calls, causing a kernel oops condition that results in a denial of service.
References: https://ubuntu.com/security/CVE-2022-2153, https://access.redhat.com/security/cve/CVE-2022-2153, https://git.kernel.org/pub/scm/virt/kvm/kvm.git/commit/?h=queue&id=00b5f37189d24ac3ed46cb7f11742094778c46c, https://www.openwall.com/lists/oss-security/2022/06/22/1, https://ubuntu.com/security/notices/USN-5727-1, https://ubuntu.com/security/notices/USN-5728-1, https://ubuntu.com/security/notices/USN-5727-2, https://ubuntu.com/security/notices/USN-5728-2, https://ubuntu.com/security/notices/USN-5728-3, https://ubuntu.com/security/notices/USN-5774-1, https://www.cve.org/CVERecord?id=CVE-2022-2153
Affected packages
Package
Name: linux-azure
Purl: pkg:deb/ubuntu/linux-azure?arch=source&distro=trusty%2Fesm
Affected ranges
Type: ECOSYSTEM
Events:
