Lucene search

K
ubuntucveUbuntu.comUB:CVE-2022-39189
HistorySep 02, 2022 - 12:00 a.m.

CVE-2022-39189

2022-09-0200:00:00
ubuntu.com
ubuntu.com
66
cve-2022-39189
unprivileged guest users
tlb flush operations
kvm_vcpu_preempted
kernel compromise
linux kernel

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

0.0004 Low

EPSS

Percentile

14.3%

An issue was discovered the x86 KVM subsystem in the Linux kernel before
5.18.17. Unprivileged guest users can compromise the guest kernel because
TLB flush operations are mishandled in certain KVM_VCPU_PREEMPTED
situations.

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

0.0004 Low

EPSS

Percentile

14.3%