CVE-2022-23035
Summary
| CVE | CVE-2022-23035 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-01-25 14:15:00 UTC |
| Updated | 2023-11-07 03:44:00 UTC |
| Description | Insufficient cleanup of passed-through device IRQs The management of IRQs associated with physical devices exposed to x86 HVM guests involves an iterative operation in particular when cleaning up after the guest's use of the device. In the case where an interrupt is not quiescent yet at the time this cleanup gets invoked, the cleanup attempt may be scheduled to be retried. When multiple interrupts are involved, this scheduling of a retry may get erroneously skipped. At the same time pointers may get cleared (resulting in a de-reference of NULL) and freed (resulting in a use-after-free), while other code would continue to assume them to be valid. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Debian -- Security Information -- DSA-5117-1 xen |
DEBIAN |
www.debian.org |
|
| oss-security - Xen Security Advisory 395 v2 (CVE-2022-23035) - Insufficient
cleanup of passed-through device IRQs |
MLIST |
www.openwall.com |
|
| xenbits.xenproject.org/xsa/advisory-395.txt |
MISC |
xenbits.xenproject.org |
|
| Xen: Multiple Vulnerabilities (GLSA 202208-23) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| [SECURITY] Fedora 34 Update: xen-4.14.4-1.fc34 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 34 Update: xen-4.14.4-1.fc34 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Array
Legacy QID Mappings
- 179182 Debian Security Update for xen (DSA 5117-1)
- 184264 Debian Security Update for xen (CVE-2022-23035)
- 282332 Fedora Security Update for xen (FEDORA-2022-420bf9fc1e)
- 282411 Fedora Security Update for xen (FEDORA-2022-0cc3916e08)
- 377775 Security Advisory for Citrix XenServer (CTX337526)
- 500806 Alpine Linux Security Update for xen
- 501523 Alpine Linux Security Update for xen
- 501801 Alpine Linux Security Update for xen
- 502242 Alpine Linux Security Update for xen
- 504548 Alpine Linux Security Update for xen
- 710600 Gentoo Linux Xen Multiple Vulnerabilities (GLSA 202208-23)
- 751685 SUSE Enterprise Linux Security Update for xen (SUSE-SU-2022:0331-1)
- 751686 SUSE Enterprise Linux Security Update for xen (SUSE-SU-2022:0332-1)
- 751691 OpenSUSE Security Update for xen (openSUSE-SU-2022:0333-1)
- 751693 SUSE Enterprise Linux Security Update for xen (SUSE-SU-2022:0359-1)
- 751713 SUSE Enterprise Linux Security Update for xen (SUSE-SU-2022:0468-1)
- 751714 SUSE Enterprise Linux Security Update for xen (SUSE-SU-2022:0469-1)
- 751717 SUSE Enterprise Linux Security Update for xen (SUSE-SU-2022:0467-1)
- 752015 SUSE Enterprise Linux Security Update for xen (SUSE-SU-2022:0333-1)
- 753138 SUSE Enterprise Linux Security Update for xen (SUSE-SU-2022:14886-1)