CVE-2022-42335
Summary
| CVE | CVE-2022-42335 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-04-25 13:15:00 UTC |
| Updated | 2024-02-04 08:15:00 UTC |
| Description | x86 shadow paging arbitrary pointer dereference In environments where host assisted address translation is necessary but Hardware Assisted Paging (HAP) is unavailable, Xen will run guests in so called shadow mode. Due to too lax a check in one of the hypervisor routines used for shadow page handling it is possible for a guest with a PCI device passed through to cause the hypervisor to access an arbitrary pointer partially under guest control. |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|
| Operating System |
Fedoraproject |
Fedora |
38 |
All |
All |
All |
| Operating System |
Xen |
Xen |
4.17.0 |
All |
All |
All |
References
| Reference | Source | Link | Tags |
|---|
| Xen: Multiple Vulnerabilities (GLSA 202402-07) — Gentoo security |
|
security.gentoo.org |
|
| xenbits.xenproject.org/xsa/advisory-430.txt |
MISC |
xenbits.xenproject.org |
|
| [SECURITY] Fedora 38 Update: xen-4.17.0-9.fc38 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| XSA-430 - Xen Security Advisories |
CONFIRM |
xenbits.xen.org |
|
| [SECURITY] Fedora 38 Update: xen-4.17.0-9.fc38 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| oss-security - Xen Security Advisory 430 v2 (CVE-2022-42335) - x86 shadow paging
arbitrary pointer dereference |
MLIST |
www.openwall.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Array
Legacy QID Mappings
- 182109 Debian Security Update for xen (CVE-2022-42335)
- 284159 Fedora Security Update for xen (FEDORA-2023-d28433ead1)
- 503145 Alpine Linux Security Update for xen
- 505966 Alpine Linux Security Update for xen
- 710858 Gentoo Linux Xen Multiple Vulnerabilities (GLSA 202402-07)