Tracker / CVE-2022-1158
CVE-2022-1158
High 7.8
A flaw was found in KVM. When updating a guest's page table entry, vm_pgoff was improperly used as the offset to get the page's pfn. As vaddr and vm_pgoff are controllable by user-mode processes, this flaw allows unprivileged local users on the host to write outside the userspace region and potentially corrupt the kernel, resulting in a denial of service condition.
Affected products and versions
| fedoraproject | fedora |
|---|---|
| linux | linux_kernel · 5.11 → 5.15.33 |
| linux | linux_kernel · 5.16 → 5.16.19 |
| linux | linux_kernel · 5.17 → 5.17.2 |
| linux | linux_kernel · 5.2 → 5.4.189 |
| linux | linux_kernel · 5.5 → 5.10.110 |
| redhat | enterprise_linux |
Analysis
This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.