PT-2023-14105 · Xen+1 · Xen+1

Roger Pau

+1

·

Publicado

2023-04-25

·

Atualizado

2024-06-15

·

CVE-2022-42335

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Xen (affected versions not specified)
Description The issue arises in environments where host assisted address translation is necessary but Hardware Assisted Paging (HAP) is unavailable, causing Xen to run guests in shadow mode. Due to insufficient checks in hypervisor routines for shadow page handling, a guest with a passed-through PCI device can cause the hypervisor to access an arbitrary pointer partially under guest control.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

NULL Pointer Dereference

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2022-42335
OPENSUSE-SU-2024:12917-1
SUSE-SU-2023:2535-1
SUSE-SU-2023_2535-1

Produtos afetados

Suse
Xen