Tracker / CVE-2022-2196
CVE-2022-2196
Media 5.8
A regression exists in the Linux Kernel within KVM: nVMX that allowed for speculative execution attacks. L2 can carry out Spectre v2 attacks on L1 due to L1 thinking it doesn't need retpolines or IBPB after running L2 due to KVM (L0) advertising eIBRS support to L1. An attacker at L2 with code execution can execute code on an indirect branch on the host machine. We recommend upgrading to Kernel 6.2 or applying the relevant stable backports (v5.4.233, v5.10.170, v5.15.96, v6.1.14).
Prodotti e versioni affette
| debian | debian_linux |
|---|---|
| linux | linux_kernel · 5.11 → 5.15.96 |
| linux | linux_kernel · 5.16 → 6.1.14 |
| linux | linux_kernel · 5.4.47 → 5.4.233 |
| linux | linux_kernel · 5.6.19 → 5.7 |
| linux | linux_kernel · 5.7.3 → 5.10.170 |
Analisi
Questa pagina non è ancora indicizzabile.Finché non contiene un’analisi originale — cosa espone davvero, come verificare in due minuti se un sistema è stato toccato, cosa fare se lo è stato — la pagina resta noindex. È il database a deciderlo, non il modello di pagina.