{"api_version":"1","generated_at":"2026-04-23T03:06:38+00:00","cve":"CVE-2022-33746","urls":{"html":"https://cve.report/CVE-2022-33746","api":"https://cve.report/api/cve/CVE-2022-33746.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2022-33746","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2022-33746"},"summary":{"title":"CVE-2022-33746","description":"P2M pool freeing may take excessively long The P2M pool backing second level address translation for guests may be of significant size. Therefore its freeing may take more time than is reasonable without intermediate preemption checks. Such checking for the need to preempt was so far missing.","state":"PUBLIC","assigner":"security@xen.org","published_at":"2022-10-11 13:15:00","updated_at":"2024-02-04 08:15:00"},"problem_types":["CWE-404"],"metrics":[],"references":[{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XWSC77GS5NATI3TT7FMVPULUPXR635XQ/","name":"FEDORA-2022-5b594b82ac","refsource":"","tags":[],"title":"[SECURITY] Fedora 36 Update: xen-4.16.2-2.fc36 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://xenbits.xen.org/xsa/advisory-410.html","name":"http://xenbits.xen.org/xsa/advisory-410.html","refsource":"CONFIRM","tags":[],"title":"XSA-410 - Xen Security Advisories","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TJOMUNGW6VTK5CZZRLWLVVEOUPEQBRHI/","name":"FEDORA-2022-d80cc73088","refsource":"FEDORA","tags":[],"title":"[SECURITY] Fedora 37 Update: xen-4.16.2-2.fc37 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://security.gentoo.org/glsa/202402-07","name":"GLSA-202402-07","refsource":"","tags":[],"title":"Xen: Multiple Vulnerabilities (GLSA 202402-07) — Gentoo security","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.debian.org/security/2022/dsa-5272","name":"DSA-5272","refsource":"DEBIAN","tags":[],"title":"Debian -- Security Information -- DSA-5272-1 xen","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"http://www.openwall.com/lists/oss-security/2022/10/11/3","name":"[oss-security] 20221011 Xen Security Advisory 410 v3 (CVE-2022-33746) - P2M pool freeing may take excessively long","refsource":"MLIST","tags":[],"title":"oss-security - Xen Security Advisory 410 v3 (CVE-2022-33746) - P2M pool freeing\n may take excessively long","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XWSC77GS5NATI3TT7FMVPULUPXR635XQ/","name":"FEDORA-2022-5b594b82ac","refsource":"FEDORA","tags":[],"title":"[SECURITY] Fedora 36 Update: xen-4.16.2-2.fc36 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://xenbits.xenproject.org/xsa/advisory-410.txt","name":"https://xenbits.xenproject.org/xsa/advisory-410.txt","refsource":"MISC","tags":[],"title":"","mime":"text/plain","httpstatus":"200","archivestatus":"404"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TJOMUNGW6VTK5CZZRLWLVVEOUPEQBRHI/","name":"FEDORA-2022-d80cc73088","refsource":"","tags":[],"title":"[SECURITY] Fedora 37 Update: xen-4.16.2-2.fc37 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YZVXG7OOOXCX6VIPEMLFDPIPUTFAYWPE/","name":"FEDORA-2022-99af00f60e","refsource":"FEDORA","tags":[],"title":"[SECURITY] Fedora 35 Update: xen-4.15.3-7.fc35 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YZVXG7OOOXCX6VIPEMLFDPIPUTFAYWPE/","name":"FEDORA-2022-99af00f60e","refsource":"","tags":[],"title":"[SECURITY] Fedora 35 Update: xen-4.15.3-7.fc35 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2022-33746","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2022-33746","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"LEGACY","value":"Array","lang":""}],"nvd_cpes":[{"cve_year":"2022","cve_id":"33746","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"debian","cpe5":"debian_linux","cpe6":"11.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2022","cve_id":"33746","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"fedoraproject","cpe5":"fedora","cpe6":"35","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2022","cve_id":"33746","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"fedoraproject","cpe5":"fedora","cpe6":"36","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2022","cve_id":"33746","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"fedoraproject","cpe5":"fedora","cpe6":"37","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2022","cve_id":"33746","vulnerable":"1","versionEndIncluding":"4.16.1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"xen","cpe5":"xen","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2022-33746","qid":"181193","title":"Debian Security Update for xen (DSA 5272-1)"},{"cve":"CVE-2022-33746","qid":"182954","title":"Debian Security Update for xen (CVE-2022-33746)"},{"cve":"CVE-2022-33746","qid":"283267","title":"Fedora Security Update for xen (FEDORA-2022-5b594b82ac)"},{"cve":"CVE-2022-33746","qid":"283319","title":"Fedora Security Update for xen (FEDORA-2022-99af00f60e)"},{"cve":"CVE-2022-33746","qid":"283476","title":"Fedora Security Update for xen (FEDORA-2022-d80cc73088)"},{"cve":"CVE-2022-33746","qid":"390270","title":"Oracle VM Server for x86 Security Update for xen (OVMSA-2022-0029)"},{"cve":"CVE-2022-33746","qid":"502600","title":"Alpine Linux Security Update for xen"},{"cve":"CVE-2022-33746","qid":"502619","title":"Alpine Linux Security Update for xen"},{"cve":"CVE-2022-33746","qid":"503143","title":"Alpine Linux Security Update for xen"},{"cve":"CVE-2022-33746","qid":"503695","title":"Alpine Linux Security Update for xen"},{"cve":"CVE-2022-33746","qid":"504549","title":"Alpine Linux Security Update for xen"},{"cve":"CVE-2022-33746","qid":"505964","title":"Alpine Linux Security Update for xen"},{"cve":"CVE-2022-33746","qid":"710858","title":"Gentoo Linux Xen Multiple Vulnerabilities (GLSA 202402-07)"},{"cve":"CVE-2022-33746","qid":"752684","title":"SUSE Enterprise Linux Security Update for xen (SUSE-SU-2022:3665-1)"},{"cve":"CVE-2022-33746","qid":"752715","title":"SUSE Enterprise Linux Security Update for xen (SUSE-SU-2022:3727-1)"},{"cve":"CVE-2022-33746","qid":"752719","title":"SUSE Enterprise Linux Security Update for xen (SUSE-SU-2022:3728-1)"},{"cve":"CVE-2022-33746","qid":"752778","title":"SUSE Enterprise Linux Security Update for xen (SUSE-SU-2022:3925-1)"},{"cve":"CVE-2022-33746","qid":"752781","title":"SUSE Enterprise Linux Security Update for xen (SUSE-SU-2022:3928-1)"},{"cve":"CVE-2022-33746","qid":"752792","title":"SUSE Enterprise Linux Security Update for xen (SUSE-SU-2022:3947-1)"},{"cve":"CVE-2022-33746","qid":"752796","title":"SUSE Enterprise Linux Security Update for xen (SUSE-SU-2022:3971-1)"},{"cve":"CVE-2022-33746","qid":"752807","title":"SUSE Enterprise Linux Security Update for xen (SUSE-SU-2022:4007-1)"},{"cve":"CVE-2022-33746","qid":"752887","title":"SUSE Enterprise Linux Security Update for xen (SUSE-SU-2022:4241-1)"}]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"security@xen.org","ID":"CVE-2022-33746","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"xen","version":{"version_data":[{"version_affected":"?","version_value":"consult Xen advisory XSA-410"}]}}]},"vendor_name":"Xen"}]}},"configuration":{"configuration_data":{"description":{"description_data":[{"lang":"eng","value":"All Xen versions are vulnerable.\n\nx86 HVM and PVH guests as well as Arm guests can trigger the\nvulnerability.  x86 PV guests cannot trigger the vulnerability."}]}}},"credit":{"credit_data":{"description":{"description_data":[{"lang":"eng","value":"This issue was discovered by Julien Grall of Amazon."}]}}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"P2M pool freeing may take excessively long The P2M pool backing second level address translation for guests may be of significant size. Therefore its freeing may take more time than is reasonable without intermediate preemption checks. Such checking for the need to preempt was so far missing."}]},"impact":{"impact_data":{"description":{"description_data":[{"lang":"eng","value":"A group of collaborating guests can cause the temporary locking up of a\nCPU, potentially leading to a Denial of Service (DoS) affecting the\nentire host."}]}}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"unknown"}]}]},"references":{"reference_data":[{"url":"https://xenbits.xenproject.org/xsa/advisory-410.txt","refsource":"MISC","name":"https://xenbits.xenproject.org/xsa/advisory-410.txt"},{"refsource":"CONFIRM","name":"http://xenbits.xen.org/xsa/advisory-410.html","url":"http://xenbits.xen.org/xsa/advisory-410.html"},{"refsource":"MLIST","name":"[oss-security] 20221011 Xen Security Advisory 410 v3 (CVE-2022-33746) - P2M pool freeing may take excessively long","url":"http://www.openwall.com/lists/oss-security/2022/10/11/3"},{"refsource":"FEDORA","name":"FEDORA-2022-5b594b82ac","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XWSC77GS5NATI3TT7FMVPULUPXR635XQ/"},{"refsource":"DEBIAN","name":"DSA-5272","url":"https://www.debian.org/security/2022/dsa-5272"},{"refsource":"FEDORA","name":"FEDORA-2022-d80cc73088","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TJOMUNGW6VTK5CZZRLWLVVEOUPEQBRHI/"},{"refsource":"FEDORA","name":"FEDORA-2022-99af00f60e","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YZVXG7OOOXCX6VIPEMLFDPIPUTFAYWPE/"}]},"workaround":{"workaround_data":{"description":{"description_data":[{"lang":"eng","value":"Running only PV guests will avoid the vulnerability."}]}}}},"nvd":{"publishedDate":"2022-10-11 13:15:00","lastModifiedDate":"2024-02-04 08:15:00","problem_types":["CWE-404"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"},"exploitabilityScore":2,"impactScore":4}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:xen:xen:*:*:*:*:*:*:*:*","versionStartIncluding":"4.13.0","versionEndIncluding":"4.16.1","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":null,"notes":[]}}}