CVE-2022-33744
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Arm guests can cause Dom0 DoS via PV devices When mapping pages of guests on Arm, dom0 is using an rbtree to keep track of the foreign mappings. Updating of that rbtree is not always done completely with the related lock held, resulting in a small race window, which can be used by unprivileged guests via PV devices to cause inconsistencies of the rbtree. These inconsistencies can lead to Denial of Service (DoS) of dom0, e.g. by causing crashes or the inability to perform further mappings of other guests' memory pages.
Los invitados Arm pueden causar DoS Dom0 por medio de dispositivos PV Al mapear páginas de invitados en Arm, dom0 está utilizando un rbtree para llevar a cabo un seguimiento de las asignaciones externas. La actualización de ese rbtree no siempre es realizado completamente con el bloqueo relacionado, resultando en una pequeña ventana de carrera, que invitados no privilegiados pueden usar por medio de dispositivos PV para causar inconsistencias en el rbtree. Estas incoherencias pueden dar lugar a la denegación de servicio (DoS) de dom0, por ejemplo, provocando bloqueos o imposibilidad de llevar a cabo más asignaciones de las páginas de memoria de otros invitados
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-06-15 CVE Reserved
- 2022-07-05 CVE Published
- 2023-10-10 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
https://lists.debian.org/debian-lts-announce/2022/10/msg00000.html | Mailing List |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.openwall.com/lists/oss-security/2022/07/05/4 | 2022-10-29 | |
http://xenbits.xen.org/xsa/advisory-406.html | 2022-10-29 |
URL | Date | SRC |
---|---|---|
https://www.debian.org/security/2022/dsa-5191 | 2022-10-29 | |
https://xenbits.xenproject.org/xsa/advisory-406.txt | 2022-10-29 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | >= 3.13 <= 5.18 Search vendor "Linux" for product "Linux Kernel" and version " >= 3.13 <= 5.18" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 10.0 Search vendor "Debian" for product "Debian Linux" and version "10.0" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 11.0 Search vendor "Debian" for product "Debian Linux" and version "11.0" | - |
Affected
|