CVE-2022-49565 is a medium-severity vulnerability in the Linux kernel's perf/x86/intel/lbr component, specifically affecting Intel LBR functionality. It arises from an unchecked MSR access error on Haswell processors when TSX is disabled and the LBR format is LBR_FORMAT_EIP_FLAGS2, due to incorrect timing of a TSX quirk application. An authenticated local attacker can exploit this with low complexity to cause a denial of service (system crash), but there is no impact on confidentiality or integrity. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.17.1, < 5.18.15CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
5.17CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:5.17:-:*:*:*:*:*:* | ||
5.17CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:5.17:rc2:*:*:*:*:*:* | ||
5.17CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:5.17:rc3:*:*:*:*:*:* | ||
5.17CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:5.17:rc4:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.