CVE-2022-39189

high
Published 2023-05-09 · Modified 2023-05-19
CVSS v3
CVSS v2
VIR risk
8.0

Description

An issue was discovered the x86 KVM subsystem in the Linux kernel before 5.18.17. Unprivileged guest users can compromise the guest kernel because TLB flush operations are mishandled in certain KVM_VCPU_PREEMPTED situations.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: alma — https://errata.almalinux.org/9/ALSA-2023-2148.html

vendor Authored 2026-05-27

Vendor advisory: alma — https://errata.almalinux.org/9/ALSA-2023-2458.html

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2177371

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2165741

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2147364

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2139610

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2134380

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2133490

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2107924

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2106830

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2089701

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2073091

vendor Authored 2026-05-27

Vendor advisory: alma — https://errata.almalinux.org/8/ALSA-2023-2736.html

vendor Authored 2026-05-27

Vendor advisory: alma — https://access.redhat.com/errata/RHSA-2023:2736

vendor Authored 2026-05-27

Vendor advisory: alma — https://errata.almalinux.org/8/ALSA-2023-2951.html

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2180936

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2176192

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2168297

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2168246

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2165721

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2162120

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2160023

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2154235

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2154171

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2151270

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2150999

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2150979

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2150960

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2150947

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2144720

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2143943

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2143893

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2137979

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2134528

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2134517

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2134506

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2134451

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2134377

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2133483

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2130141

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2127985

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2124788

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2123056

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2122960

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2122228

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2114937

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2108696

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2108691

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2090723

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2085300

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2084125

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2078466

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2061703

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2055499

vendor Authored 2026-05-27

Vendor advisory: alma — https://access.redhat.com/errata/RHSA-2023:2951

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2022-39189

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2022-39189.html

vendor Authored 2026-05-27

Vendor advisory: redhat — https://access.redhat.com/errata/RHSA-2023:2458

vendor Authored 2026-05-27

Vendor advisory: redhat — https://access.redhat.com/errata/RHSA-2023:2148

Mitigation details

Source: Red Hat Errata — Red Hat Inc. · View original ↗ · Open-Errata-API

Description kernel: TLB flush operations are mishandled in certain KVM_VCPU_PREEMPTED leading to guest malfunctioning Red Hat statement With the current usecase, attacker need a root privileges to exploit this flaw, however there may have ways to defeat this either, but in both cases it seems that Attack Complexity is high (AC:H) CVSS v3: 7.0 (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H) Errata…

Description

kernel: TLB flush operations are mishandled in certain KVM_VCPU_PREEMPTED leading to guest malfunctioning

Red Hat statement

With the current usecase, attacker need a root privileges to exploit this flaw, however there may have ways to defeat this either, but in both cases it seems that Attack Complexity is high (AC:H)

CVSS v3: 7.0 (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H)

Errata / fixed releases

ProductPackageAdvisoryReleased
Red Hat Enterprise Linux 8kernel-rt-0:4.18.0-477.10.1.rt7.274.el8_8RHSA-2023:27362023-05-16T00:00:00Z
Red Hat Enterprise Linux 8kernel-0:4.18.0-477.10.1.el8_8RHSA-2023:29512023-05-16T00:00:00Z
Red Hat Enterprise Linux 8.6 Extended Update Supportkernel-0:4.18.0-372.91.1.el8_6RHSA-2024:07242024-02-07T00:00:00Z
Red Hat Enterprise Linux 9kernel-0:5.14.0-284.11.1.el9_2RHSA-2023:24582023-05-09T00:00:00Z
Red Hat Enterprise Linux 9kernel-rt-0:5.14.0-284.11.1.rt14.296.el9_2RHSA-2023:21482023-05-09T00:00:00Z
Red Hat Enterprise Linux 9kernel-0:5.14.0-284.11.1.el9_2RHSA-2023:24582023-05-09T00:00:00Z
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8kernel-0:4.18.0-372.91.1.el8_6RHSA-2024:07242024-02-07T00:00:00Z

Package state

ProductPackageState
Red Hat Enterprise Linux 6kernelNot affected
Red Hat Enterprise Linux 7kernelOut of support scope
Red Hat Enterprise Linux 7kernel-rtOut of support scope

Apply commands

bash fix
Apply RHSA-2023:2736 for Red Hat Enterprise Linux 8
yum update -y kernel-rt
# or:
dnf upgrade -y kernel-rt

Affected

VendorProductVersion
redhatRed Hat Enterprise Linux 6Not affected

OS impact

OSVersionStatusFixed in
redhat rhel9fixed
suse slesaffected
debian debianbookwormfixed5.19.6-1
debian debianbullseyefixed5.10.191-1
debian debianforkyfixed5.19.6-1
debian debiansidfixed5.19.6-1
debian debiantrixiefixed5.19.6-1
almalinux almalinux8fixedkernel-doc-4.18.0-477.10.1.el8_8.noarch.rpm
almalinux almalinux9fixedkernel-doc-5.14.0-284.11.1.el9_2.noarch.rpm

References

Verify integrity in audit chain (admin only). AS-IS.