CVE-2022-49611 Details
Description
In the Linux kernel, the following vulnerability has been resolved: x86/speculation: Fill RSB on vmexit for IBRS Prevent RSB underflow/poisoning attacks with RSB. While at it, add a bunch of comments to attempt to document the current state of tribal knowledge about RSB attacks and what exactly is being mitigated.
A vulnerability in the Linux kernel related to RSB (Return Stack Buffer) underflow and poisoning attacks has been addressed. This issue was particularly relevant for x86 architecture, where the kernel now fills the RSB on vmexit for IBRS (Indirect Branch Restricted Speculation) to prevent such underflow attacks. The vulnerability arose from the need to document and mitigate tribal knowledge about RSB attacks and their implications.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/17a9fc4a7b91f8599223631bb6ae6416bc0de1c0 | kernel.org | Patch |
| https://git.kernel.org/stable/c/3d323b99ff5c8c57005184056d65f6af5b0479d8 | kernel.org | Patch |
| https://git.kernel.org/stable/c/4d7f72b6e1bc630bec7e4cd51814bc2b092bf153 | kernel.org | Patch |
| https://git.kernel.org/stable/c/8c38306e2e9257af4af2819aa287a4711ff36329 | kernel.org | Patch |
| https://git.kernel.org/stable/c/8d5cff499a6d740c91ff37963907e0e983c37f0f | kernel.org | Patch |
| https://git.kernel.org/stable/c/9756bba28470722dacb79ffce554336dd1f6a6cd | kernel.org | Patch |
| https://git.kernel.org/stable/c/f744b88dfc201bf8092833ec70b23c720188b527 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | < 4.14.297 >= 4.15, < 4.19.266 >= 4.20, < 5.4.217 >= 5.5, < 5.10.133 >= 5.11, < 5.15.57 >= 5.16, < 5.18.14 5.19 rc1 5.19 rc2 5.19 rc3 5.19 rc4 5.19 rc5 5.19 rc6 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| Oct 23, 2025 | Initial Analysis | [email protected] |
| Feb 26, 2025 | New CVE Received | kernel.org |