CVE-2022-3707 is a double-free flaw in the Linux kernel's Intel GVT-g graphics virtualization driver. Under high DMA load, failure of intel_gvt_dma_map_guest_page() can cause ppgtt_invalidate_spt() to free an SPT object before error handling in split_2MB_gtt_entry frees it again, enabling a local user to trigger a system crash or resource-exhaustion condition. Red Hat rates the issue Moderate, with a CVSS score of 5.1 and primary impact to availability.
Upstream maintainers corrected the memory-management path by separating SPT invalidation from deallocation, adding ppgtt_invalidate_and_free_spt() so objects are freed only after successful invalidation. The fix was included in Fedora kernel 6.1.5 and backported to Linux 6.0.19; Red Hat shipped updates for affected RHEL 8, RHEL 9, RHEL 8.6 EUS, and Red Hat Virtualization 4 deployments. RHEL 6 and RHEL 7 variants are not affected.

See affected versions and whether adversaries are exploiting it.
6 events from the most recent confirmed update back to the earliest known activity.
Red Hat released RHSA-2023:2736 for the RHEL 8 kernel-rt package and RHSA-2023:2951 for the RHEL 8 kernel package, addressing CVE-2022-3707.
Red Hat shipped fixes for CVE-2022-3707 for Red Hat Enterprise Linux 9 through RHSA-2023:2148 for kernel-rt and RHSA-2023:2458 for the kernel package.
Fedora fixed the Intel GVT-g double-free issue through its Linux 6.1.5 stable-kernel rebase. The fix was also backported to Linux kernel 6.0.19.
RHSA-2024:0724 delivered fixes for the RHEL 8.6 Extended Update Support kernel package and the Red Hat Virtualization 4 for RHEL 8 kernel package.
Red Hat closed Bugzilla bug 2137979, its tracking record for the Linux Intel GVT-g double-free vulnerability, while further product updates remained tracked on the CVE page.
Zheng Wang submitted version 3 of a patch for the DRM i915 GVT code to prevent an SPT object from being freed twice after intel_gvt_dma_map_guest_page() fails. The patch separated SPT invalidation from deallocation in drivers/gpu/drm/i915/gvt/gtt.c.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
redhat.com
Open sourcebugzilla.redhat.com
Open sourcelore.kernel.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.