PT-2022-21858 · Arm+1 · Arm+1
Published
2022-10-11
·
Updated
2024-02-04
·
CVE-2022-33747
CVSS v3.1
3.8
Low
| Vector | AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
Arm versions (affected versions not specified)
Description
The issue concerns unbounded memory consumption for 2nd-level page tables. Certain actions, such as removing pages from a guest's P2M (Physical-to-Machine) mapping, may incur memory allocations from the global memory pool when large pages are used to map guest pages in the 2nd-stage page tables. A malicious guest could potentially exhaust the global memory pool by manipulating its own P2M mappings.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Resource Release
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Arm
Suse