PT-2022-17810 · Suse · Suse

Jan Beulich

+1

·

Published

2022-04-05

·

Updated

2024-02-04

·

CVE-2022-26359

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions No specific software or versions are mentioned in the provided descriptions.
Description The issue concerns IOMMU: RMRR (VT-d) and unity map (AMD-Vi) handling problems. Certain PCI devices in a system might be assigned Reserved Memory Regions for Intel VT-d or Unity Mapping ranges for AMD-Vi, typically used for platform tasks such as legacy USB emulation. Since the precise purpose of these regions is unknown, once a device associated with such a region is active, the mappings of these regions need to remain continuously accessible by the device. This requirement has been violated, potentially leading to unpredictable behavior, ranging from IOMMU faults to memory corruption.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Related Identifiers

CVE-2022-26359
DSA-5117-1
OPENSUSE-SU-2022_1506-1
OPENSUSE-SU-2022_2065-1
SUSE-SU-2022:1285-1
SUSE-SU-2022:1300-1
SUSE-SU-2022:1359-1
SUSE-SU-2022:1375-1
SUSE-SU-2022:1408-1
SUSE-SU-2022:1505-1
SUSE-SU-2022:1506-1
SUSE-SU-2022:2065-1
SUSE-SU-2022:2158-1
SUSE-SU-2022_1505-1
SUSE-SU-2022_1506-1

Affected Products

Suse