Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Daniel Jordan

Researcher fromOracle
#45655of 53,635
5.5Total CVSS
Vulnerabilities · 1
PT-2022-7617
5.5
2022-02-14
Linux · Linux Kernel · CVE-2022-48904
**Name of the Vulnerable Software and Affected Versions** Linux kernel versions prior to the fix **Description** The issue is related to a memory leak in the IOMMU page table, which can be observed when launching VM with pass-through devices. This is due to the current logic updating the I/O page table mode for the domain before calling the logic to free memory used for the page table. The estimated number of potentially affected devices is not specified. There is no information about real-world incidents where this issue was exploited. **Recommendations** To resolve the issue, update to a version of the Linux kernel that includes the fix for the I/O page table memory leak. As a temporary workaround, consider disabling the launch of VM with pass-through devices until a patch is available. Restrict access to the vulnerable `iommu/amd` component to minimize the risk of exploitation.