« Volver al listado

CVE-2022-2196

Estado: ModificadaAlta (8.8)—

Existe una regresión en el kernel de Linux dentro de KVM: nVMX que permitió ataques de ejecución especulativa. L2 puede llevar a cabo ataques Spectre v2 en L1 debido a que L1 piensa que no necesita retpolines o IBPB después de ejecutar L2 debido a que KVM (L0) anuncia soporte eIBRS en L1. Un atacante en L2 con ejecución de código puede ejecutar código en una rama indirecta en la máquina host. Recomendamos actualizar al Kernel 6.2 o al commit anterior 2e7eab81425a

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-2196",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2022-2196",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-08-01T15:07:47.721131Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "cve-coordination@google.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.8,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:L",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "LOW",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 4.7,
        "exploitabilityScore": 1
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 6,
        "exploitabilityScore": 2
      }
    ]
  },
  "affected": [
    {
      "source": "cve-coordination@google.com",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git",
          "vendor": "Linux",
          "product": "Linux Kernel",
          "versions": [
            {
              "status": "affected",
              "version": "64b8f33b2e1e687d465b5cb382e7bec495f1e026",
              "lessThan": "f93a1a5bdcdd122aae0a3eab7a52c15b71fb725b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e089a83fbc55b8057f332c00f125acaa02b08ef7",
              "lessThan": "2e7eab81425ad6c875f2ed47c0ce01e78afc38a5",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "02a3868d18fe639363f1cea6e6d7914513198e43",
              "lessThan": "2e7eab81425ad6c875f2ed47c0ce01e78afc38a5",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5c911beff20aa8639e7a1f28988736c13e03ed54",
              "lessThan": "1b0cafaae8884726c597caded50af185ffc13349",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5c911beff20aa8639e7a1f28988736c13e03ed54",
              "lessThan": "6b539a7dbb49250f92515c2ba60aea239efc9e35",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5c911beff20aa8639e7a1f28988736c13e03ed54",
              "lessThan": "63fada296062e91ad9f871970d4e7f19e21a6a15",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5c911beff20aa8639e7a1f28988736c13e03ed54",
              "lessThan": "2e7eab81425ad6c875f2ed47c0ce01e78afc38a5",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5.4.47",
              "lessThan": "5.4.233",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "5.6.19",
              "lessThan": "5.7.0",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "5.7.3",
              "lessThan": "5.8.0",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "5.8.0",
              "lessThan": "5.10.170",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "5.11.0",
              "lessThan": "5.15.96",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "5.16.0",
              "lessThan": "6.1.14",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.2.0",
              "versionType": "semver"
            }
          ],
          "packageName": "KVM",
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2023-01-09T11:15:10.583",
  "references": [
    {
      "url": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=1b0cafaae8884726c597caded50af185ffc13349",
      "source": "cve-coordination@google.com"
    },
    {
      "url": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=63fada296062e91ad9f871970d4e7f19e21a6a15",
      "source": "cve-coordination@google.com"
    },
    {
      "url": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=6b539a7dbb49250f92515c2ba60aea239efc9e35",
      "source": "cve-coordination@google.com"
    },
    {
      "url": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=f93a1a5bdcdd122aae0a3eab7a52c15b71fb725b",
      "source": "cve-coordination@google.com"
    },
    {
      "url": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=2e7eab81425ad6c875f2ed47c0ce01e78afc38a5",
      "tags": [
        "Mailing List",
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve-coordination@google.com"
    },
    {
      "url": "https://kernel.dance/#2e7eab81425a",
      "tags": [
        "Patch",
        "Third Party Advisory"
      ],
      "source": "cve-coordination@google.com"
    },
    {
      "url": "https://lists.debian.org/debian-lts-announce/2023/05/msg00005.html",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "cve-coordination@google.com"
    },
    {
      "url": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=2e7eab81425ad6c875f2ed47c0ce01e78afc38a5",
      "tags": [
        "Mailing List",
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://kernel.dance/#2e7eab81425a",
      "tags": [
        "Patch",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://lists.debian.org/debian-lts-announce/2023/05/msg00005.html",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://security.netapp.com/advisory/ntap-20230223-0002/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cve-coordination@google.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-1188"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-1188"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A regression exists in the Linux Kernel within KVM: nVMX that allowed for speculative execution attacks. L2 can carry out Spectre v2 attacks on L1 due to L1 thinking it doesn't need retpolines or IBPB after running L2 due to KVM (L0) advertising eIBRS support to L1. An attacker at L2 with code execution can execute code on an indirect branch on the host machine. We recommend upgrading to Kernel 6.2 or applying the relevant stable backports (v5.4.233, v5.10.170, v5.15.96, v6.1.14)."
    },
    {
      "lang": "es",
      "value": "Existe una regresión en el kernel de Linux dentro de KVM: nVMX que permitió ataques de ejecución especulativa. L2 puede llevar a cabo ataques Spectre v2 en L1 debido a que L1 piensa que no necesita retpolines o IBPB después de ejecutar L2 debido a que KVM (L0) anuncia soporte eIBRS en L1. Un atacante en L2 con ejecución de código puede ejecutar código en una rama indirecta en la máquina host. Recomendamos actualizar al Kernel 6.2 o al commit anterior 2e7eab81425a"
    }
  ],
  "lastModified": "2026-08-07T19:17:31.747",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D73442D9-8AEA-46EF-BDFE-A7DA3F4256CB",
              "versionEndExcluding": "5.4.233",
              "versionStartIncluding": "5.4.47"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1D059EB4-CC70-4B73-A918-FCD19DD26EEF",
              "versionEndExcluding": "5.7",
              "versionStartIncluding": "5.6.19"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A90F1F96-608E-46B6-848B-CAAA543D8E77",
              "versionEndExcluding": "5.10.170",
              "versionStartIncluding": "5.7.3"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0845BF9E-3498-4C4E-AE1E-2F4FD31B440E",
              "versionEndExcluding": "5.15.96",
              "versionStartIncluding": "5.11"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E5FED97E-E13D-4287-892D-F8A8C081B5EA",
              "versionEndExcluding": "6.1.14",
              "versionStartIncluding": "5.16"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "07B237A9-69A3-4A9C-9DA0-4E06BD37AE73"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve-coordination@google.com"
}