CVE-2022-33743
Summary
| CVE | CVE-2022-33743 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-07-05 13:15:00 UTC |
| Updated | 2022-11-05 03:06:00 UTC |
| Description | network backend may cause Linux netfront to use freed SKBs While adding logic to support XDP (eXpress Data Path), a code label was moved in a way allowing for SKBs having references (pointers) retained for further processing to nevertheless be freed. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 11.0 | All | All | All |
| Operating System | Linux | Linux Kernel | All | All | All | All |
| Operating System | Xen | Xen | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| oss-security - Xen Security Advisory 405 v3 (CVE-2022-33743) - network backend may cause Linux netfront to use freed SKBs | MLIST | www.openwall.com | |
| xenbits.xenproject.org/xsa/advisory-405.txt | MISC | xenbits.xenproject.org | |
| Debian -- Security Information -- DSA-5191-1 linux | DEBIAN | www.debian.org | |
| XSA-405 - Xen Security Advisories | CONFIRM | xenbits.xen.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Array
Legacy QID Mappings
- 160583 Oracle Enterprise Linux Security Update for kernel (ELSA-2023-2458)
- 180900 Debian Security Update for linux (DSA 5191-1)
- 183403 Debian Security Update for linux (CVE-2022-33743)
- 198948 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-5624-1)
- 198950 Ubuntu Security Notification for Linux kernel (HWE) Vulnerabilities (USN-5623-1)
- 198953 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-5633-1)
- 198958 Ubuntu Security Notification for Linux kernel (GKE) Vulnerabilities (USN-5635-1)
- 198960 Ubuntu Security Notification for Linux kernel (Oracle) Vulnerabilities (USN-5640-1)
- 198964 Ubuntu Security Notification for Linux kernel (GCP) Vulnerabilities (USN-5644-1)
- 198967 Ubuntu Security Notification for Linux kernel (GKE) Vulnerabilities (USN-5648-1)
- 198972 Ubuntu Security Notification for Linux kernel (Intel IoTG) Vulnerabilities (USN-5655-1)
- 198989 Ubuntu Security Notification for Linux kernel (IBM) Vulnerabilities (USN-5683-1)
- 199073 Ubuntu Security Notification for Linux kernel (OEM) Vulnerabilities (USN-5773-1)
- 199084 Ubuntu Security Notification for Linux kernel (OEM) Vulnerabilities (USN-5789-1)
- 241417 Red Hat Update for kernel security (RHSA-2023:2458)
- 241468 Red Hat Update for kernel-rt (RHSA-2023:2148)
- 354016 Amazon Linux Security Advisory for kernel : ALAS2KERNEL-5.10-2022-018
- 354020 Amazon Linux Security Advisory for kernel : ALAS2KERNEL-5.15-2022-005
- 354270 Amazon Linux Security Advisory for kernel : ALAS2022-2022-114
- 354468 Amazon Linux Security Advisory for kernel : ALAS2022-2022-185
- 354542 Amazon Linux Security Advisory for kernel : ALAS-2022-185
- 355199 Amazon Linux Security Advisory for kernel : ALAS2023-2023-070
- 377117 Alibaba Cloud Linux Security Update for cloud-kernel (ALINUX3-SA-2022:0158)
- 502600 Alpine Linux Security Update for xen
- 503695 Alpine Linux Security Update for xen
- 6140354 AWS Bottlerocket Security Update for kernel (GHSA-w8jq-c399-98rh)
- 752370 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:2520-1)
- 753148 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:2615-1)
- 753491 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 0 for SLE 15 SP4) (SUSE-SU-2022:2854-1)
- 902459 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (10122)
- 902466 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (10103)
- 902518 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (10107)
- 904115 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (10107-1)
- 904196 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (10120-1)
- 906196 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (10120-2)
- 906452 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (10107-2)
- 941023 AlmaLinux Security Update for kernel (ALSA-2023:2458)
- 941061 AlmaLinux Security Update for kernel-rt (ALSA-2023:2148)