CVE-2022-33748
Summary
| CVE | CVE-2022-33748 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-10-11 13:15:00 UTC |
| Updated | 2024-02-04 08:15:00 UTC |
| Description | lock order inversion in transitive grant copy handling As part of XSA-226 a missing cleanup call was inserted on an error handling path. While doing so, locking requirements were not paid attention to. As a result two cooperating guests granting each other transitive grants can cause locks to be acquired nested within one another, but in respectively opposite order. With suitable timing between the involved grant copy operations this may result in the locking up of a CPU. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] Fedora 36 Update: xen-4.16.2-2.fc36 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| xenbits.xenproject.org/xsa/advisory-411.txt |
MISC |
xenbits.xenproject.org |
|
| [SECURITY] Fedora 37 Update: xen-4.16.2-2.fc37 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| Xen: Multiple Vulnerabilities (GLSA 202402-07) — Gentoo security |
|
security.gentoo.org |
|
| XSA-411 - Xen Security Advisories |
CONFIRM |
xenbits.xen.org |
|
| Debian -- Security Information -- DSA-5272-1 xen |
DEBIAN |
www.debian.org |
|
| oss-security - Xen Security Advisory 411 v3 (CVE-2022-33748) - lock order
inversion in transitive grant copy handling |
MLIST |
www.openwall.com |
|
| [SECURITY] Fedora 36 Update: xen-4.16.2-2.fc36 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 37 Update: xen-4.16.2-2.fc37 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 35 Update: xen-4.15.3-7.fc35 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 35 Update: xen-4.15.3-7.fc35 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Array
Legacy QID Mappings
- 181193 Debian Security Update for xen (DSA 5272-1)
- 182696 Debian Security Update for xen (CVE-2022-33748)
- 283267 Fedora Security Update for xen (FEDORA-2022-5b594b82ac)
- 283319 Fedora Security Update for xen (FEDORA-2022-99af00f60e)
- 283476 Fedora Security Update for xen (FEDORA-2022-d80cc73088)
- 502600 Alpine Linux Security Update for xen
- 502619 Alpine Linux Security Update for xen
- 503143 Alpine Linux Security Update for xen
- 503695 Alpine Linux Security Update for xen
- 504549 Alpine Linux Security Update for xen
- 505964 Alpine Linux Security Update for xen
- 710858 Gentoo Linux Xen Multiple Vulnerabilities (GLSA 202402-07)
- 752684 SUSE Enterprise Linux Security Update for xen (SUSE-SU-2022:3665-1)
- 752715 SUSE Enterprise Linux Security Update for xen (SUSE-SU-2022:3727-1)
- 752719 SUSE Enterprise Linux Security Update for xen (SUSE-SU-2022:3728-1)
- 752778 SUSE Enterprise Linux Security Update for xen (SUSE-SU-2022:3925-1)
- 752781 SUSE Enterprise Linux Security Update for xen (SUSE-SU-2022:3928-1)
- 752792 SUSE Enterprise Linux Security Update for xen (SUSE-SU-2022:3947-1)
- 752796 SUSE Enterprise Linux Security Update for xen (SUSE-SU-2022:3971-1)
- 752807 SUSE Enterprise Linux Security Update for xen (SUSE-SU-2022:4007-1)
- 752887 SUSE Enterprise Linux Security Update for xen (SUSE-SU-2022:4241-1)