CVE-2022-26356
published 2022-04-05CVE-2022-26356: Racy interactions between dirty vram tracking and paging log dirty hypercalls Activation of log dirty mode done by XEN_DMOP_track_dirty_vram (was named…
PriorityP420medium5.6CVSS 3.1
AVLACHPRLUINSCCNINAH
EPSS
0.23%
14.1th percentile
Racy interactions between dirty vram tracking and paging log dirty hypercalls Activation of log dirty mode done by XEN_DMOP_track_dirty_vram (was named HVMOP_track_dirty_vram before Xen 4.9) is racy with ongoing log dirty hypercalls. A suitably timed call to XEN_DMOP_track_dirty_vram can enable log dirty while another CPU is still in the process of tearing down the structures related to a previously enabled log dirty mode (XEN_DOMCTL_SHADOW_OP_OFF). This is due to lack of mutually exclusive locking between both operations and can lead to entries being added in already freed slots, resulting in a memory leak.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | xen | < xen 4.16.1-1 (bookworm) | xen 4.16.1-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| xen | xen | >= 0 < 4.14.4+74-gd7b22226b5-1 | 4.14.4+74-gd7b22226b5-1 |
| xen | xen | >= 0 < 4.16.1-1 | 4.16.1-1 |
| xen | xen | >= 0 < 4.16.1-1 | 4.16.1-1 |
| xen | xen | >= 0 < 4.16.1-1 | 4.16.1-1 |
| xen | xen | >= 4.0.0 < 4.12.0 | 4.12.0 |
| xen | xen | >= 4.13.0 < 4.14.0 | 4.14.0 |
| xen | xen | >= 4.15.0 < 4.16.0 | 4.16.0 |
CVSS provenance
nvdv3.15.6MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H
nvdv2.04.0MEDIUMAV:L/AC:H/Au:N/C:N/I:N/A:C
osv5.6MEDIUM
vendor_debian5.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wqf3-h5g7-w9q8: Racy interactions between dirty vram tracking and paging log dirty hypercalls Activation of log dirty mode done by XEN_DMOP_track_dirty_vram (was name
ghsa_unreviewed·2022-04-06
CVE-2022-26356 [MEDIUM] CWE-667 GHSA-wqf3-h5g7-w9q8: Racy interactions between dirty vram tracking and paging log dirty hypercalls Activation of log dirty mode done by XEN_DMOP_track_dirty_vram (was name
Racy interactions between dirty vram tracking and paging log dirty hypercalls Activation of log dirty mode done by XEN_DMOP_track_dirty_vram (was named HVMOP_track_dirty_vram before Xen 4.9) is racy with ongoing log dirty hypercalls. A suitably timed call to XEN_DMOP_track_dirty_vram can enable log dirty while another CPU is still in the process of tearing down the structures related to a previously enabled log dirty mode (XEN_DOMCTL_SHADOW_OP_OFF). This is due to lack of mutually exclusive locking between both operations and can lead to entries being added in already freed slots, resulting in a memory leak.
OSV
CVE-2022-26356: Racy interactions between dirty vram tracking and paging log dirty hypercalls Activation of log dirty mode done by XEN_DMOP_track_dirty_vram (was name
osv·2022-04-05·CVSS 5.6
CVE-2022-26356 [MEDIUM] CVE-2022-26356: Racy interactions between dirty vram tracking and paging log dirty hypercalls Activation of log dirty mode done by XEN_DMOP_track_dirty_vram (was name
Racy interactions between dirty vram tracking and paging log dirty hypercalls Activation of log dirty mode done by XEN_DMOP_track_dirty_vram (was named HVMOP_track_dirty_vram before Xen 4.9) is racy with ongoing log dirty hypercalls. A suitably timed call to XEN_DMOP_track_dirty_vram can enable log dirty while another CPU is still in the process of tearing down the structures related to a previously enabled log dirty mode (XEN_DOMCTL_SHADOW_OP_OFF). This is due to lack of mutually exclusive locking between both operations and can lead to entries being added in already freed slots, resulting in a memory leak.
Debian
CVE-2022-26356: xen - Racy interactions between dirty vram tracking and paging log dirty hypercalls Ac...
vendor_debian·2022·CVSS 5.6
CVE-2022-26356 [MEDIUM] CVE-2022-26356: xen - Racy interactions between dirty vram tracking and paging log dirty hypercalls Ac...
Racy interactions between dirty vram tracking and paging log dirty hypercalls Activation of log dirty mode done by XEN_DMOP_track_dirty_vram (was named HVMOP_track_dirty_vram before Xen 4.9) is racy with ongoing log dirty hypercalls. A suitably timed call to XEN_DMOP_track_dirty_vram can enable log dirty while another CPU is still in the process of tearing down the structures related to a previously enabled log dirty mode (XEN_DOMCTL_SHADOW_OP_OFF). This is due to lack of mutually exclusive locking between both operations and can lead to entries being added in already freed slots, resulting in a memory leak.
Scope: local
bookworm: resolved (fixed in 4.16.1-1)
bullseye: resolved (fixed in 4.14.4+74-gd7b22226b5-1)
forky: resolved (fixed in 4.16.1-1)
sid: resolved (fixed in 4.16.1-1)
trixie:
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.openwall.com/lists/oss-security/2022/04/05/1http://xenbits.xen.org/xsa/advisory-397.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6ETPM2OVZZ6KOS2L7QO7SIW6XWT5OW3F/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UHFSRVLM2JUCPDC2KGB7ETPQYJLCGBLD/https://security.gentoo.org/glsa/202402-07https://www.debian.org/security/2022/dsa-5117https://xenbits.xenproject.org/xsa/advisory-397.txthttp://www.openwall.com/lists/oss-security/2022/04/05/1http://xenbits.xen.org/xsa/advisory-397.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6ETPM2OVZZ6KOS2L7QO7SIW6XWT5OW3F/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UHFSRVLM2JUCPDC2KGB7ETPQYJLCGBLD/https://security.gentoo.org/glsa/202402-07https://www.debian.org/security/2022/dsa-5117https://xenbits.xenproject.org/xsa/advisory-397.txt
2022-04-05
Published