
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2022-49054 affects the Linux kernel's Hyper-V vmbus driver. The vulnerability was discovered when it was found that hv_panic_page might contain guest-sensitive information that could be exposed by dumping it to Hyper-V in isolated guest environments. The issue was reported by Dexuan Cui and resolved through a patch that deactivates sysctl_record_panic_msg by default in isolated guests (Kernel Git).
The vulnerability exists in the Linux kernel's vmbus driver for Hyper-V. The issue involves the sysctl_record_panic_msg functionality, which was previously enabled by default even in isolated guest environments. The fix modifies the vmbus_bus_init function to check if isolation is supported (hv_is_isolation_supported()) and if so, deactivates sysctl_record_panic_msg by default. The patch also updates comments in hyperv_{panic,die}_event() functions for better clarity (Kernel Git). The vulnerability has been assigned a CVSS v3.1 base score of 5.5 with vector AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H (Red Hat).
The vulnerability could potentially expose sensitive guest information through the hv_panic_page when panic messages are recorded and dumped to Hyper-V in isolated guest environments (Kernel Git).
The vulnerability requires local access and low privileges to exploit. It specifically affects isolated guest environments running on Hyper-V where the panic message recording feature is enabled (Red Hat).
The vulnerability has been patched by modifying the default behavior of sysctl_record_panic_msg to be disabled in isolated guest environments. The fix has been implemented in the Linux kernel, ensuring that guest-sensitive information is not inadvertently exposed through panic message dumps (Kernel Git).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."