CVE-2022-33745
published 2022-07-26CVE-2022-33745: insufficient TLB flush for x86 PV guests in shadow mode For migration as well as to work around kernels unaware of L1TF (see XSA-273), PV guests may be run in…
PriorityP342high8.8CVSS 3.1
AVLACLPRLUINSCCHIHAH
EPSS
0.30%
22.1th percentile
insufficient TLB flush for x86 PV guests in shadow mode For migration as well as to work around kernels unaware of L1TF (see XSA-273), PV guests may be run in shadow paging mode. To address XSA-401, code was moved inside a function in Xen. This code movement missed a variable changing meaning / value between old and new code positions. The now wrong use of the variable did lead to a wrong TLB flush condition, omitting flushes where such are necessary.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | xen | < xen 4.16.2-1 (bookworm) | xen 4.16.2-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| xen | xen | >= 0 < 4.14.5+86-g1c354767d5-1 | 4.14.5+86-g1c354767d5-1 |
| xen | xen | >= 0 < 4.16.2-1 | 4.16.2-1 |
| xen | xen | >= 0 < 4.16.2-1 | 4.16.2-1 |
| xen | xen | >= 0 < 4.16.2-1 | 4.16.2-1 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
osv8.8HIGH
vendor_debian8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2022-33745: xen - insufficient TLB flush for x86 PV guests in shadow mode For migration as well as...
vendor_debian·2022·CVSS 8.8
CVE-2022-33745 [HIGH] CVE-2022-33745: xen - insufficient TLB flush for x86 PV guests in shadow mode For migration as well as...
insufficient TLB flush for x86 PV guests in shadow mode For migration as well as to work around kernels unaware of L1TF (see XSA-273), PV guests may be run in shadow paging mode. To address XSA-401, code was moved inside a function in Xen. This code movement missed a variable changing meaning / value between old and new code positions. The now wrong use of the variable did lead to a wrong TLB flush condition, omitting flushes where such are necessary.
Scope: local
bookworm: resolved (fixed in 4.16.2-1)
bullseye: resolved (fixed in 4.14.5+86-g1c354767d5-1)
forky: resolved (fixed in 4.16.2-1)
sid: resolved (fixed in 4.16.2-1)
trixie: resolved (fixed in 4.16.2-1)
GHSA
GHSA-f5vc-gmmj-gpp6: insufficient TLB flush for x86 PV guests in shadow mode For migration as well as to work around kernels unaware of L1TF (see XSA-273), PV guests may b
ghsa_unreviewed·2022-07-27
CVE-2022-33745 [HIGH] GHSA-f5vc-gmmj-gpp6: insufficient TLB flush for x86 PV guests in shadow mode For migration as well as to work around kernels unaware of L1TF (see XSA-273), PV guests may b
insufficient TLB flush for x86 PV guests in shadow mode For migration as well as to work around kernels unaware of L1TF (see XSA-273), PV guests may be run in shadow paging mode. To address XSA-401, code was moved inside a function in Xen. This code movement missed a variable changing meaning / value between old and new code positions. The now wrong use of the variable did lead to a wrong TLB flush condition, omitting flushes where such are necessary.
OSV
CVE-2022-33745: insufficient TLB flush for x86 PV guests in shadow mode For migration as well as to work around kernels unaware of L1TF (see XSA-273), PV guests may b
osv·2022-07-26·CVSS 8.8
CVE-2022-33745 [HIGH] CVE-2022-33745: insufficient TLB flush for x86 PV guests in shadow mode For migration as well as to work around kernels unaware of L1TF (see XSA-273), PV guests may b
insufficient TLB flush for x86 PV guests in shadow mode For migration as well as to work around kernels unaware of L1TF (see XSA-273), PV guests may be run in shadow paging mode. To address XSA-401, code was moved inside a function in Xen. This code movement missed a variable changing meaning / value between old and new code positions. The now wrong use of the variable did lead to a wrong TLB flush condition, omitting flushes where such are necessary.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.openwall.com/lists/oss-security/2022/07/26/2http://www.openwall.com/lists/oss-security/2022/07/26/3http://xenbits.xen.org/xsa/advisory-408.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HUFIMNGYP5VQAA6KE3T2I5GW6UP6F7BS/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MYI3OMJ7RIZNL3C6GUWNANNPEUUID6FM/https://www.debian.org/security/2022/dsa-5272https://xenbits.xenproject.org/xsa/advisory-408.txthttp://www.openwall.com/lists/oss-security/2022/07/26/2http://www.openwall.com/lists/oss-security/2022/07/26/3http://xenbits.xen.org/xsa/advisory-408.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HUFIMNGYP5VQAA6KE3T2I5GW6UP6F7BS/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MYI3OMJ7RIZNL3C6GUWNANNPEUUID6FM/https://www.debian.org/security/2022/dsa-5272https://xenbits.xenproject.org/xsa/advisory-408.txt
2022-07-26
Published