CVE-2022-45869: Race Condition
A race condition in the x86 KVM subsystem in the Linux kernel through 6.1-rc6 allows guest OS users to cause a denial of service (host OS crash or host OS memory corruption) when nested virtualisation and the TDP MMU are enabled.
Other sources
Linux Kernel is vulnerable to a denial of service, caused by a race condition in the x86 KVM subsystem when nested virtualisation and the TDP MMU are enabled. By sending a specially-crafted request, a local authenticated attacker could exploit this vulnerability to cause the system to crash.
— IBM
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-45869?
CVE-2022-45869 is rated as a high severity vulnerability that can lead to denial of service attacks.
How do I fix CVE-2022-45869?
To mitigate CVE-2022-45869, upgrade to kernel versions 6.1.123-1 or higher, or apply the relevant patches provided by your distribution.
Which systems are affected by CVE-2022-45869?
CVE-2022-45869 affects the Linux kernel versions up to and including 6.1-rc6 as well as specific IBM Security Verify Governance components.
What kind of attack does CVE-2022-45869 enable?
CVE-2022-45869 allows attackers to exploit a race condition that may result in host OS crashes or memory corruption.
How can I determine if my system is vulnerable to CVE-2022-45869?
You can determine vulnerability by checking your Linux kernel version or the affected software components against the CVE-2022-45869 details.