CVE-2022-26357
Summary
| CVE | CVE-2022-26357 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-04-05 13:15:00 UTC |
| Updated | 2024-02-04 08:15:00 UTC |
| Description | race in VT-d domain ID cleanup Xen domain IDs are up to 15 bits wide. VT-d hardware may allow for only less than 15 bits to hold a domain ID associating a physical device with a particular domain. Therefore internally Xen domain IDs are mapped to the smaller value range. The cleaning up of the housekeeping structures has a race, allowing for VT-d domain IDs to be leaked and flushes to be bypassed. |
NVD Known Affected Configurations (CPE 2.3)
Vendor Comments And Credit
Discovery Credit
LEGACY: Array
Legacy QID Mappings
- 179182 Debian Security Update for xen (DSA 5117-1)
- 183995 Debian Security Update for xen (CVE-2022-26357)
- 282617 Fedora Security Update for xen (FEDORA-2022-dfbf7e2372)
- 282643 Fedora Security Update for xen (FEDORA-2022-64b2c02d29)
- 377773 Citrix XenServer Security Update (CTX390511)
- 390260 Oracle Managed Virtualization (VM) Server for x86 Security Update for xen (OVMSA-2022-0012)
- 500806 Alpine Linux Security Update for xen
- 501523 Alpine Linux Security Update for xen
- 502242 Alpine Linux Security Update for xen
- 502421 Alpine Linux Security Update for xen
- 504548 Alpine Linux Security Update for xen
- 710858 Gentoo Linux Xen Multiple Vulnerabilities (GLSA 202402-07)
- 752054 SUSE Enterprise Linux Security Update for xen (SUSE-SU-2022:1285-1)
- 752065 SUSE Enterprise Linux Security Update for xen (SUSE-SU-2022:1300-1)
- 752073 SUSE Enterprise Linux Security Update for xen (SUSE-SU-2022:1359-1)
- 752075 SUSE Enterprise Linux Security Update for xen (SUSE-SU-2022:1408-1)
- 752099 SUSE Enterprise Linux Security Update for xen (SUSE-SU-2022:1506-1)
- 752100 SUSE Enterprise Linux Security Update for xen (SUSE-SU-2022:1505-1)
- 752262 SUSE Enterprise Linux Security Update for xen (SUSE-SU-2022:2158-1)