vulnerability

Amazon Linux AMI: CVE-2022-48991: Security patch for kernel (ALAS-2023-1706)

Severity
7
CVSS
(AV:L/AC:L/Au:S/C:C/I:C/A:C)
Published
2023-03-20
Added
2025-01-23
Modified
2025-05-20

Description

In the Linux kernel, the following vulnerability has been resolved:



mm/khugepaged: invoke MMU notifiers in shmem/file collapse paths



Any codepath that zaps page table entries must invoke MMU notifiers to


ensure that secondary MMUs (like KVM) don't keep accessing pages which


aren't mapped anymore. Secondary MMUs don't hold their own references to


pages that are mirrored over, so failing to notify them can lead to page


use-after-free.



I'm marking this as addressing an issue introduced in commit f3f0e1d2150b


("khugepaged: add support of collapse for tmpfs/shmem pages"), but most of


the security impact of this only came in commit 27e1f8273113 ("khugepaged:


enable collapse pmd for pte-mapped THP"), which actually omitted flushes


for the removal of present PTEs, not just for the removal of empty page


tables.

Solution

amazon-linux-upgrade-kernel
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.