CVE-2022-1852 is a moderate-severity NULL-pointer dereference in the Linux kernel's x86 KVM instruction-emulation path. A low-privileged attacker in an Intel-based virtual-machine guest can execute an illegal instruction and trigger a fault in x86_emulate_insn, causing a denial of service. Red Hat assigned a CVSS v3.1 score of 5.5 and classified the defect as CWE-476.
The upstream Linux fix, commit fee060cd52d69c114b62d1a2948ea9648b5131f9, prevents KVM from invoking the x86 emulator before an instruction has been decoded, avoiding use of stale emulation context after breakpoint-related handling. Red Hat released corrected kernel packages for affected RHEL 8 and RHEL 9 systems and related products; RHEL 6 and 7 kernels are not affected. Where patching cannot be performed promptly, Red Hat recommends blacklisting the affected KVM kernel module at boot to prevent it from loading.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
Red Hat released RHSA-2022:7444 for RHEL 8 kernel-rt and RHSA-2022:7683 for the RHEL 8 kernel, addressing the KVM NULL-pointer-dereference denial-of-service vulnerability.
Paolo Bonzini committed Sean Christopherson's patch to prevent x86 KVM instruction emulation from running before an instruction is decoded. The fix was marked for stable-kernel backporting.
Red Hat released RHSA-2024:1877 to fix CVE-2022-1852 for the RHEL 8.6 Extended Update Support kernel and Red Hat Virtualization 4 for RHEL 8.
Red Hat released RHSA-2022:8267 for the RHEL 9 kernel and RHSA-2022:7933 for RHEL 9 kernel-rt to fix CVE-2022-1852.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.