GSD-2022-1005535

Source
https://data.gsd.id/GSD-2022-1005535
Import Source
https://github.com/cloudsecurityalliance/gsd-database/blob/main/2022/1005xxx/GSD-2022-1005535.json
JSON Data
https://api.osv.dev/v1/vulns/GSD-2022-1005535
Published
2022-09-17T00:04:26.489244Z
Modified
2023-02-22T10:35:04.031102Z
Summary
KVM: Unconditionally get a ref to /dev/kvm module when creating a VM
Details

KVM: Unconditionally get a ref to /dev/kvm module when creating a VM

This is an automated ID intended to aid in discovery of potential security vulnerabilities. The actual impact and attack plausibility have not yet been proven. This ID is fixed in Linux Kernel version v5.15.63 by commit 177bf354200962c6f0de6dd37c86a9bf3b54003a, it was introduced in version v5.15.33 by commit 43637ee17092eef0b97a327bb4355230060431c4. For more details please see the references link.

References

Affected packages

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/
Events
Introduced
43637ee17092eef0b97a327bb4355230060431c4
Limit
177bf354200962c6f0de6dd37c86a9bf3b54003a

Affected versions

v5.*
v5.15.33
v5.15.34
v5.15.35
v5.15.36
v5.15.37
v5.15.38
v5.15.39
v5.15.40
v5.15.41
v5.15.42
v5.15.43
v5.15.44
v5.15.45
v5.15.46
v5.15.47
v5.15.48
v5.15.49
v5.15.50
v5.15.51
v5.15.52
v5.15.53
v5.15.54
v5.15.55
v5.15.56
v5.15.57
v5.15.58
v5.15.59
v5.15.60
v5.15.61
v5.15.62

Database specific

source
"https://github.com/cloudsecurityalliance/gsd-database/blob/main/2022/1005xxx/GSD-2022-1005535.json"