CVE-2022-39189 affects the Linux kernel’s x86 KVM subsystem, where instruction emulation can leave the KVM_VCPU_PREEMPTED flag set and mishandle paravirtualized TLB flushes. Other guest vCPUs may then skip required TLB-flush IPIs while emulation accesses memory using stale guest-virtual translations, enabling an unprivileged user inside a VM to compromise the guest kernel or cause guest malfunction. The issue affects the KVM_FEATURE_PV_TLB_FLUSH functionality introduced in Linux 4.16 and was demonstrated through emulated VMMCALL and port-I/O operations.
The upstream correction, commit 6cd88243c7e03845a450795e134b488fc2afb736, was merged for Linux 5.19 and backported to the stable 5.15 and 5.18 kernel trees; affected kernels are generally versions before 5.18.17. Red Hat rated the vulnerability Moderate with CVSS 7.0 and issued fixes for affected RHEL 8, RHEL 8 kernel-rt, RHEL 8.6 EUS, RHEL 9, RHEL 9 kernel-rt, and Red Hat Virtualization 4 on RHEL 8 packages; Red Hat reported no qualifying mitigation, making deployment of the relevant kernel updates the required remediation.

Get the actors, campaigns, and ATT&CK mapping behind it.
6 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2023:2736 for RHEL 8 kernel-rt and RHSA-2023:2951 for RHEL 8 kernel packages. Red Hat also closed bug 2124788 for CVE-2022-39189.
Red Hat issued RHSA-2023:2148 and RHSA-2023:2458 to remediate CVE-2022-39189 in RHEL 9 kernel-rt and kernel packages, respectively.
Rohit Keshri reported Red Hat bug 2124788 to track the x86 KVM flaw, which can allow an unprivileged KVM guest user to compromise the guest kernel.
Linux merged commit 6cd88243c7e03845a450795e134b488fc2afb736 to fix mishandled TLB flushes involving KVM_VCPU_PREEMPTED and instruction emulation.
Red Hat issued RHSA-2024:0724 to fix CVE-2022-39189 in RHEL 8.6 Extended Update Support kernel packages and Red Hat Virtualization 4 for RHEL 8 kernel packages.
The upstream fix for CVE-2022-39189 was included in the Linux 5.19 release. The fix was also manually backported to the 5.15 and 5.18 stable trees.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
4 references tracked. Mallory keeps watching after this page renders.
redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugs.chromium.org
Open sourcegit.kernel.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.