Insecure Default Initialization of Resource Affecting perf package, versions <0:4.18.0-372.93.1.el8_6
Threat Intelligence
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-RHEL8-PERF-6261332
- published 21 Feb 2024
- disclosed 28 Sep 2022
Introduced: 28 Sep 2022
CVE-2022-2196 Open this link in a new tabHow to fix?
Upgrade RHEL:8
perf
to version 0:4.18.0-372.93.1.el8_6 or higher.
This issue was patched in RHSA-2024:0930
.
NVD Description
Note: Versions mentioned in the description apply only to the upstream perf
package and not the perf
package as distributed by RHEL
.
See How to fix?
for RHEL:8
relevant fixed versions and status.
A regression exists in the Linux Kernel within KVM: nVMX that allowed for speculative execution attacks. L2 can carry out Spectre v2 attacks on L1 due to L1 thinking it doesn't need retpolines or IBPB after running L2 due to KVM (L0) advertising eIBRS support to L1. An attacker at L2 with code execution can execute code on an indirect branch on the host machine. We recommend upgrading to Kernel 6.2 or past commit 2e7eab81425a
References
- https://access.redhat.com/security/cve/CVE-2022-2196
- https://security.netapp.com/advisory/ntap-20230223-0002/
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=2e7eab81425ad6c875f2ed47c0ce01e78afc38a5
- https://kernel.dance/#2e7eab81425a
- https://lists.debian.org/debian-lts-announce/2023/05/msg00005.html