CVE-2022-33747
published 2022-10-11CVE-2022-33747: Arm: unbounded memory consumption for 2nd-level page tables Certain actions require e.g. removing pages from a guest's P2M (Physical-to-Machine) mapping. When…
PriorityP413low3.8CVSS 3.1
AVLACLPRLUINSCCNINAL
EPSS
0.26%
17.3th percentile
Arm: unbounded memory consumption for 2nd-level page tables Certain actions require e.g. removing pages from a guest's P2M (Physical-to-Machine) mapping. When large pages are in use to map guest pages in the 2nd-stage page tables, such a removal operation may incur a memory allocation (to replace a large mapping with individual smaller ones). These memory allocations are taken from the global memory pool. A malicious guest might be able to cause the global memory pool to be exhausted by manipulating its own P2M mappings.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | xen | < xen 4.16.2+90-g0d39a6d1ae-1 (bookworm) | xen 4.16.2+90-g0d39a6d1ae-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| xen | xen | >= 0 < 4.14.5+86-g1c354767d5-1 | 4.14.5+86-g1c354767d5-1 |
| xen | xen | >= 0 < 4.16.2+90-g0d39a6d1ae-1 | 4.16.2+90-g0d39a6d1ae-1 |
| xen | xen | >= 0 < 4.16.2+90-g0d39a6d1ae-1 | 4.16.2+90-g0d39a6d1ae-1 |
| xen | xen | >= 0 < 4.16.2+90-g0d39a6d1ae-1 | 4.16.2+90-g0d39a6d1ae-1 |
CVSS provenance
nvdv3.13.8LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L
osv3.8LOW
vendor_debian3.8LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wp5g-757j-v342: Arm: unbounded memory consumption for 2nd-level page tables Certain actions require e
ghsa_unreviewed·2022-10-11
CVE-2022-33747 [LOW] CWE-400 GHSA-wp5g-757j-v342: Arm: unbounded memory consumption for 2nd-level page tables Certain actions require e
Arm: unbounded memory consumption for 2nd-level page tables Certain actions require e.g. removing pages from a guest's P2M (Physical-to-Machine) mapping. When large pages are in use to map guest pages in the 2nd-stage page tables, such a removal operation may incur a memory allocation (to replace a large mapping with individual smaller ones). These memory allocations are taken from the global memory pool. A malicious guest might be able to cause the global memory pool to be exhausted by manipulating its own P2M mappings.
OSV
CVE-2022-33747: Arm: unbounded memory consumption for 2nd-level page tables Certain actions require e
osv·2022-10-11·CVSS 3.8
CVE-2022-33747 [LOW] CVE-2022-33747: Arm: unbounded memory consumption for 2nd-level page tables Certain actions require e
Arm: unbounded memory consumption for 2nd-level page tables Certain actions require e.g. removing pages from a guest's P2M (Physical-to-Machine) mapping. When large pages are in use to map guest pages in the 2nd-stage page tables, such a removal operation may incur a memory allocation (to replace a large mapping with individual smaller ones). These memory allocations are taken from the global memory pool. A malicious guest might be able to cause the global memory pool to be exhausted by manipulating its own P2M mappings.
Debian
CVE-2022-33747: xen - Arm: unbounded memory consumption for 2nd-level page tables Certain actions requ...
vendor_debian·2022·CVSS 3.8
CVE-2022-33747 [LOW] CVE-2022-33747: xen - Arm: unbounded memory consumption for 2nd-level page tables Certain actions requ...
Arm: unbounded memory consumption for 2nd-level page tables Certain actions require e.g. removing pages from a guest's P2M (Physical-to-Machine) mapping. When large pages are in use to map guest pages in the 2nd-stage page tables, such a removal operation may incur a memory allocation (to replace a large mapping with individual smaller ones). These memory allocations are taken from the global memory pool. A malicious guest might be able to cause the global memory pool to be exhausted by manipulating its own P2M mappings.
Scope: local
bookworm: resolved (fixed in 4.16.2+90-g0d39a6d1ae-1)
bullseye: resolved (fixed in 4.14.5+86-g1c354767d5-1)
forky: resolved (fixed in 4.16.2+90-g0d39a6d1ae-1)
sid: resolved (fixed in 4.16.2+90-g0d39a6d1ae-1)
trixie: resolved (fixed in 4.16.2+90-g0d39a6d1ae-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.openwall.com/lists/oss-security/2022/10/11/5http://xenbits.xen.org/xsa/advisory-409.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TJOMUNGW6VTK5CZZRLWLVVEOUPEQBRHI/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XWSC77GS5NATI3TT7FMVPULUPXR635XQ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YZVXG7OOOXCX6VIPEMLFDPIPUTFAYWPE/https://security.gentoo.org/glsa/202402-07https://www.debian.org/security/2022/dsa-5272https://xenbits.xenproject.org/xsa/advisory-409.txthttp://www.openwall.com/lists/oss-security/2022/10/11/5http://xenbits.xen.org/xsa/advisory-409.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TJOMUNGW6VTK5CZZRLWLVVEOUPEQBRHI/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XWSC77GS5NATI3TT7FMVPULUPXR635XQ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YZVXG7OOOXCX6VIPEMLFDPIPUTFAYWPE/https://security.gentoo.org/glsa/202402-07https://www.debian.org/security/2022/dsa-5272https://xenbits.xenproject.org/xsa/advisory-409.txt
2022-10-11
Published