CVE-2022-42327
Summary
| CVE | CVE-2022-42327 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-11-01 13:15:00 UTC |
| Updated | 2024-02-04 08:15:00 UTC |
| Description | x86: unintended memory sharing between guests On Intel systems that support the "virtualize APIC accesses" feature, a guest can read and write the global shared xAPIC page by moving the local APIC out of xAPIC mode. Access to this shared page bypasses the expected isolation that should exist between two guests. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Fedoraproject | Fedora | 36 | All | All | All |
| Operating System | Fedoraproject | Fedora | 37 | All | All | All |
| Operating System | Xen | Xen | 4.16 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| oss-security - Xen Security Advisory 412 v2 (CVE-2022-42327) - x86: unintended memory sharing between guests | MLIST | www.openwall.com | |
| [SECURITY] Fedora 37 Update: xen-4.16.2-4.fc37 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| xenbits.xenproject.org/xsa/advisory-412.txt | MISC | xenbits.xenproject.org | |
| Xen: Multiple Vulnerabilities (GLSA 202402-07) — Gentoo security | security.gentoo.org | ||
| [SECURITY] Fedora 37 Update: xen-4.16.2-4.fc37 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| XSA-412 - Xen Security Advisories | CONFIRM | xenbits.xen.org | |
| [SECURITY] Fedora 36 Update: xen-4.16.2-3.fc36 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [SECURITY] Fedora 36 Update: xen-4.16.2-3.fc36 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Array
Legacy QID Mappings
- 183948 Debian Security Update for xen (CVE-2022-42327)
- 283293 Fedora Security Update for xen (FEDORA-2022-07438e12df)
- 283430 Fedora Security Update for xen (FEDORA-2022-9f51d13fa3)
- 502600 Alpine Linux Security Update for xen
- 502817 Alpine Linux Security Update for xen
- 503695 Alpine Linux Security Update for xen
- 505706 Alpine Linux Security Update for xen
- 710858 Gentoo Linux Xen Multiple Vulnerabilities (GLSA 202402-07)
- 752807 SUSE Enterprise Linux Security Update for xen (SUSE-SU-2022:4007-1)