VYPR
Medium severity5.8NVD Advisory· Published Jan 9, 2023· Updated Aug 7, 2026

CVE-2022-2196

CVE-2022-2196

Description

A regression exists in the Linux Kernel within KVM: nVMX that allowed for speculative execution attacks. L2 can carry out Spectre v2 attacks on L1 due to L1 thinking it doesn't need retpolines or IBPB after running L2 due to KVM (L0) advertising eIBRS support to L1. An attacker at L2 with code execution can execute code on an indirect branch on the host machine. We recommend upgrading to Kernel 6.2 or applying the relevant stable backports (v5.4.233, v5.10.170, v5.15.96, v6.1.14).

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

230

Patches

Vulnerability mechanics

References

8

News mentions

0

No linked articles in our index yet.