VYPR
High severity7.8NVD Advisory· Published May 1, 2025· Updated Aug 4, 2026

CVE-2022-49884

CVE-2022-49884

Description

In the Linux kernel, the following vulnerability has been resolved:

KVM: Initialize gfn_to_pfn_cache locks in dedicated helper

Move the gfn_to_pfn_cache lock initialization to another helper and call the new helper during VM/vCPU creation. There are race conditions possible due to kvm_gfn_to_pfn_cache_init()'s ability to re-initialize the cache's locks.

For example: a race between ioctl(KVM_XEN_HVM_EVTCHN_SEND) and kvm_gfn_to_pfn_cache_init() leads to a corrupted shinfo gpc lock.

(thread 1) | (thread 2) | kvm_xen_set_evtchn_fast | read_lock_irqsave(&gpc->lock, ...) | | kvm_gfn_to_pfn_cache_init | rwlock_init(&gpc->lock) read_unlock_irqrestore(&gpc->lock, ...) |

Rename "cache_init" and "cache_destroy" to activate+deactivate to avoid implying that the cache really is destroyed/freed.

Note, there more races in the newly named kvm_gpc_activate() that will be addressed separately.

[sean: call out that this is a bug fix]

Affected products

7
  • Linux/Kernelcpe-rescue6 versions
    5.17+ 5 more
    • (no CPE)range: 5.17
    • cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*range: >=5.17,<6.0.8
    • cpe:2.3:o:linux:linux_kernel:6.1:rc1:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:6.1:rc2:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:6.1:rc3:*:*:*:*:*:*
    • (no CPE)
  • osv-coords
    Range: >= 5.17.0, < 6.0.8

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.