CVE-2022-50228 Details
Description
In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Don't BUG if userspace injects an interrupt with GIF=0 Don't BUG/WARN on interrupt injection due to GIF being cleared, since it's trivial for userspace to force the situation via KVM_SET_VCPU_EVENTS (even if having at least a WARN there would be correct for KVM internally generated injections). kernel BUG at arch/x86/kvm/svm/svm.c:3386! invalid opcode: 0000 [#1] SMP CPU: 15 PID: 926 Comm: smm_test Not tainted 5.17.0-rc3+ #264 Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 0.0.0 02/06/2015 RIP: 0010:svm_inject_irq+0xab/0xb0 [kvm_amd] Code: <0f> 0b 0f 1f 00 0f 1f 44 00 00 80 3d ac b3 01 00 00 55 48 89 f5 53 RSP: 0018:ffffc90000b37d88 EFLAGS: 00010246 RAX: 0000000000000000 RBX: ffff88810a234ac0 RCX: 0000000000000006 RDX: 0000000000000000 RSI: ffffc90000b37df7 RDI: ffff88810a234ac0 RBP: ffffc90000b37df7 R08: ffff88810a1fa410 R09: 0000000000000000 R10: 0000000000000000 R11: 0000000000000000 R12: 0000000000000000 R13: ffff888109571000 R14: ffff88810a234ac0 R15: 0000000000000000 FS: 0000000001821380(0000) GS:ffff88846fdc0000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007f74fc550008 CR3: 000000010a6fe000 CR4: 0000000000350ea0 Call Trace: <TASK> inject_pending_event+0x2f7/0x4c0 [kvm] kvm_arch_vcpu_ioctl_run+0x791/0x17a0 [kvm] kvm_vcpu_ioctl+0x26d/0x650 [kvm] __x64_sys_ioctl+0x82/0xb0 do_syscall_64+0x3b/0xc0 entry_SYSCALL_64_after_hwframe+0x44/0xae </TASK>
A vulnerability in the Linux kernel's KVM (Kernel-based Virtual Machine) module for AMD processors has been identified. This issue arises from improper handling of interrupt injections when the GIF (Global Interrupt Flag) is cleared. Userspace can easily manipulate this situation using the KVM_SET_VCPU_EVENTS command, leading to a kernel panic. The vulnerability was introduced in version 5.17.0-rc3 and has been resolved in subsequent releases.
Users should upgrade to the latest stable version of the Linux kernel where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/2c49adeb020995236e63722ef6d0bee14372f471 | kernel.org | Patch |
| https://git.kernel.org/stable/c/2eee1dba70f57148fc7f8252613bfae6bd4b04e3 | kernel.org | Patch |
| https://git.kernel.org/stable/c/3d4e2d884da6312df7c9b85fbf671de49204ead6 | kernel.org | Patch |
| https://git.kernel.org/stable/c/68e1313bb8809e8addcd9431f2bfea0e8ddbca80 | kernel.org | Patch |
| https://git.kernel.org/stable/c/6afe88fbb40eac3291a8728688d61fdc745d8008 | kernel.org | Patch |
| https://git.kernel.org/stable/c/6fcbab82ccbcde915644085f73d3487938bda42d | kernel.org | Patch |
| https://git.kernel.org/stable/c/8bb683490278005b4caf61e22b0828a04d282e86 | kernel.org | Patch |
| https://git.kernel.org/stable/c/c3396c1c8b87510f2ac2a674948156577559d42d | kernel.org | Patch |
| https://git.kernel.org/stable/c/f17c31c48e5cde9895a491d91c424eeeada3e134 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 2.6.32, < 4.9.326 >= 4.10, < 4.14.291 >= 4.15, < 4.19.256 >= 4.20, < 5.4.211 >= 5.5, < 5.10.137 >= 5.11, < 5.15.61 >= 5.16, < 5.18.18 >= 5.19, < 5.19.2 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| Nov 19, 2025 | Initial Analysis | [email protected] |
| Jun 18, 2025 | New CVE Received | kernel.org |