CVE-2022-0171

MEDIUM

Linux Kernel - Use After Free

Title source: llm
STIX 2.1

Description

A flaw was found in the Linux kernel. The existing KVM SEV API has a vulnerability that allows a non-root (host) user-level application to crash the host kernel by creating a confidential guest VM instance in AMD CPU that supports Secure Encrypted Virtualization (SEV).

Scores

CVSS v3 5.5
EPSS 0.0016
EPSS Percentile 36.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-212 CWE-459
Status published
Products (6)
debian/debian_linux 10.0
debian/debian_linux 11.0
linux/linux_kernel 5.18 (4 CPE variants)
linux/linux_kernel < 5.18
redhat/enterprise_linux 8.0
redhat/enterprise_linux 9.0
Published Aug 26, 2022
Tracked Since Feb 18, 2026