PT-2022-17813 · Suse · Suse

Jan Beulich

+1

·

Published

2022-04-05

·

Updated

2024-02-04

·

CVE-2022-26361

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions No specific software or versions are mentioned in the provided descriptions.
Description The issue relates to IOMMU: RMRR (VT-d) and unity map (AMD-Vi) handling issues. Certain PCI devices in a system might be assigned Reserved Memory Regions for Intel VT-d or Unity Mapping ranges for AMD-Vi, typically used for platform tasks such as legacy USB emulation. Since the precise purpose of these regions is unknown, once a device associated with such a region is active, the mappings of these regions need to remain continuously accessible by the device. This requirement has been violated, resulting in unpredictable behavior, ranging from IOMMU faults to memory corruption.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Related Identifiers

CVE-2022-26361
DSA-5117-1
OPENSUSE-SU-2022_1506-1
OPENSUSE-SU-2022_2065-1
SUSE-SU-2022:1285-1
SUSE-SU-2022:1300-1
SUSE-SU-2022:1359-1
SUSE-SU-2022:1375-1
SUSE-SU-2022:1408-1
SUSE-SU-2022:1505-1
SUSE-SU-2022:1506-1
SUSE-SU-2022:2065-1
SUSE-SU-2022:2158-1
SUSE-SU-2022_1505-1
SUSE-SU-2022_1506-1

Affected Products

Suse