PT-2022-21859 · Xen+1 · Xen+1

Jan Beulich

·

Published

2022-10-11

·

Updated

2024-06-15

·

CVE-2022-33748

CVSS v3.1

5.6

Medium

VectorAV:L/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Xen (affected versions not specified)
Description The issue is related to a lock order inversion in transitive grant copy handling. This occurred after a missing cleanup call was inserted on an error handling path as part of XSA-226, without considering locking requirements. As a result, two cooperating guests granting each other transitive grants can cause locks to be acquired in a nested manner but in opposite order. With suitable timing between the involved grant copy operations, this may result in the locking up of a CPU.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Handling of Exceptional Conditions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-33748
DSA-5272-1
OPENSUSE-SU-2022_3665-1
OPENSUSE-SU-2022_3727-1
OPENSUSE-SU-2022_3947-1
OPENSUSE-SU-2022_4007-1
OPENSUSE-SU-2024:12561-1
SUSE-SU-2022:3665-1
SUSE-SU-2022:3727-1
SUSE-SU-2022:3728-1
SUSE-SU-2022:3925-1
SUSE-SU-2022:3928-1
SUSE-SU-2022:3947-1
SUSE-SU-2022:3971-1
SUSE-SU-2022:4007-1
SUSE-SU-2022:4051-1
SUSE-SU-2022:4241-1

Affected Products

Suse
Xen