CVE-2022-49883: Linux Kernel

High severity, CVSS 7.1. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: KVM: x86: smm: number of GPRs in the SMRAM image depends on the image format On 64 bit host, if the guest doesn't have X86_FEATURE_LM, KVM will access 16 gprs to 32-bit smram image, causing out-ouf-bound ram access. On 32 bit host, the rsm_load_state_64/enter_smm_save_state_64 is compiled out, thus access overflow can't happen.

Affected products

  • Linux Linux Kernel: from 6.0, before 6.0.8 (fixed in 6.0.8); version 6.1 only

Published 2025-05-01. Last modified 2026-08-04.