PT-2022-21858 · Arm+1 · Arm+1

Published

2022-10-11

·

Updated

2024-02-04

·

CVE-2022-33747

CVSS v3.1

3.8

Low

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Arm versions (affected versions not specified)
Description The issue concerns unbounded memory consumption for 2nd-level page tables. Certain actions, such as removing pages from a guest's P2M (Physical-to-Machine) mapping, may incur memory allocations from the global memory pool when large pages are used to map guest pages in the 2nd-stage page tables. A malicious guest could potentially exhaust the global memory pool by manipulating its own P2M mappings.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Resource Release

Weakness Enumeration

Related Identifiers

CVE-2022-33747
DSA-5272-1
OPENSUSE-SU-2022_3947-1
OPENSUSE-SU-2022_4007-1
SUSE-SU-2022:3947-1
SUSE-SU-2022:4007-1

Affected Products

Arm
Suse