CVE-2022-33741
Summary
| CVE | CVE-2022-33741 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-07-05 13:15:00 UTC |
| Updated | 2023-11-07 03:48:00 UTC |
| Description | Linux disk/nic frontends data leaks T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Linux Block and Network PV device frontends don't zero memory regions before sharing them with the backend (CVE-2022-26365, CVE-2022-33740). Additionally the granularity of the grant table doesn't allow sharing less than a 4K page, leading to unrelated data residing in the same 4K page as data shared with a backend being accessible by such backend (CVE-2022-33741, CVE-2022-33742). |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| xenbits.xenproject.org/xsa/advisory-403.txt |
MISC |
xenbits.xenproject.org |
|
| [SECURITY] Fedora 36 Update: xen-4.16.1-5.fc36 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] [DLA 3131-1] linux security update |
MLIST |
lists.debian.org |
|
| [SECURITY] Fedora 35 Update: xen-4.15.3-2.fc35 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| Debian -- Security Information -- DSA-5191-1 linux |
DEBIAN |
www.debian.org |
|
| [SECURITY] Fedora 35 Update: xen-4.15.3-2.fc35 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| oss-security - Xen Security Advisory 403 v3 (CVE-2022-26365,CVE-2022-33740,CVE-2022-33741,CVE-2022-33742)
- Linux disk/nic frontends data leaks |
MLIST |
www.openwall.com |
|
| XSA-403 - Xen Security Advisories |
CONFIRM |
xenbits.xen.org |
|
| [SECURITY] Fedora 36 Update: xen-4.16.1-5.fc36 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Array
Legacy QID Mappings
- 180900 Debian Security Update for linux (DSA 5191-1)
- 181091 Debian Security Update for linux (DLA 3131-1)
- 184865 Debian Security Update for xenlinux (CVE-2022-33741)
- 198948 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-5624-1)
- 198950 Ubuntu Security Notification for Linux kernel (HWE) Vulnerabilities (USN-5623-1)
- 198953 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-5633-1)
- 198958 Ubuntu Security Notification for Linux kernel (GKE) Vulnerabilities (USN-5635-1)
- 198960 Ubuntu Security Notification for Linux kernel (Oracle) Vulnerabilities (USN-5640-1)
- 198964 Ubuntu Security Notification for Linux kernel (GCP) Vulnerabilities (USN-5644-1)
- 198967 Ubuntu Security Notification for Linux kernel (GKE) Vulnerabilities (USN-5648-1)
- 198972 Ubuntu Security Notification for Linux kernel (Intel IoTG) Vulnerabilities (USN-5655-1)
- 198978 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-5669-1)
- 198980 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-5668-1)
- 198985 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-5678-1)
- 198987 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-5677-1)
- 198989 Ubuntu Security Notification for Linux kernel (IBM) Vulnerabilities (USN-5683-1)
- 198990 Ubuntu Security Notification for Linux kernel (AWS) Vulnerabilities (USN-5682-1)
- 198994 Ubuntu Security Notification for Linux kernel (Azure) Vulnerabilities (USN-5687-1)
- 199011 Ubuntu Security Notification for Linux kernel (Azure CVM) Vulnerabilities (USN-5706-1)
- 282930 Fedora Security Update for xen (FEDORA-2022-c4ec706488)
- 282969 Fedora Security Update for xen (FEDORA-2022-2c9f8224f8)
- 354002 Amazon Linux Security Advisory for kernel : ALAS2-2022-1825
- 354016 Amazon Linux Security Advisory for kernel : ALAS2KERNEL-5.10-2022-018
- 354020 Amazon Linux Security Advisory for kernel : ALAS2KERNEL-5.15-2022-005
- 354025 Amazon Linux Security Advisory for kernel : ALAS2KERNEL-5.4-2022-033
- 354030 Amazon Linux Security Advisory for kernel : ALAS-2022-1624
- 354270 Amazon Linux Security Advisory for kernel : ALAS2022-2022-114
- 354468 Amazon Linux Security Advisory for kernel : ALAS2022-2022-185
- 354542 Amazon Linux Security Advisory for kernel : ALAS-2022-185
- 355199 Amazon Linux Security Advisory for kernel : ALAS2023-2023-070
- 377117 Alibaba Cloud Linux Security Update for cloud-kernel (ALINUX3-SA-2022:0158)
- 378473 Alibaba Cloud Linux Security Update for cloud-kernel (ALINUX2-SA-2023:0021)
- 502420 Alpine Linux Security Update for xen
- 502422 Alpine Linux Security Update for xen
- 502423 Alpine Linux Security Update for xen
- 502814 Alpine Linux Security Update for xen
- 6140052 AWS Bottlerocket Security Update for kernel (GHSA-c3cw-2p8m-3568)
- 672114 EulerOS Security Update for kernel (EulerOS-SA-2022-2292)
- 672139 EulerOS Security Update for kernel (EulerOS-SA-2022-2428)
- 672158 EulerOS Security Update for kernel (EulerOS-SA-2022-2415)
- 752340 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:2377-1)
- 752349 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:2382-1)
- 752354 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:2393-1)
- 752359 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:2411-1)
- 752360 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:2407-1)
- 752370 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:2520-1)
- 752463 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:2809-1)
- 752502 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:2875-1)
- 752684 SUSE Enterprise Linux Security Update for xen (SUSE-SU-2022:3665-1)
- 752719 SUSE Enterprise Linux Security Update for xen (SUSE-SU-2022:3728-1)
- 752781 SUSE Enterprise Linux Security Update for xen (SUSE-SU-2022:3928-1)
- 753148 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:2615-1)
- 753156 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:2741-1)
- 753316 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:2892-1)