boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2022-2196HIGH
Linux Linux Kernel — Speculative execution attacks in KVM VMX
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   L   L   N  C  H  H  H    8.8   .0029   21.1     —
AFFECTED
  Product       Versions                                    Fixed
  Linux Kernel  64b8f33b2e1e687d465b5cb382e7bec495f1e026 –  6.2.0
TIMELINE
  Jun 24  Reserved by Google
  Jan 9   Published (CNA: Google)
  Aug 7   RESCORED — CVE-2022-2196 (Linux Kernel). CVSS 5.8 → 8.8 (NVD).
CWE-1188 · CNA: Google · CVSS v3.1 · 8 references · NVD status: Modified

Description

A regression exists in the Linux Kernel within KVM: nVMX that allowed for speculative execution attacks. L2 can carry out Spectre v2 attacks on L1 due to L1 thinking it doesn't need retpolines or IBPB after running L2 due to KVM (L0) advertising eIBRS support to L1. An attacker at L2 with code execution can execute code on an indirect branch on the host machine. We recommend upgrading to Kernel 6.2 or applying the relevant stable backports (v5.4.233, v5.10.170, v5.15.96, v6.1.14).

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
June 24, 2022ReservedReserved by Google
January 9, 2023PublishedPublished (CNA: Google)
August 7, 2026RESCOREDRESCORED — CVE-2022-2196 (Linux Kernel). CVSS 5.8 → 8.8 (NVD).

Affected

Affected products and packages — 1 row
VendorProduct / PackageEcosystemVersion introducedFixed
LinuxLinux Kernel64b8f33b2e1e687d465b5cb382e7bec495f1e0266.2.0

Weaknesses

CWE-1188

References (8)

Related

Authoritative record: CVE-2022-2196 at cve.org

Vendors: linux

Weaknesses: CWE-1188

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2022-2196 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.