CVE-2022-48904
published 2024-08-22CVE-2022-48904: In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Fix I/O page table memory leak The current logic updates the I/O page table mode…
PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.21%
11.2th percentile
In the Linux kernel, the following vulnerability has been resolved:
iommu/amd: Fix I/O page table memory leak
The current logic updates the I/O page table mode for the domain
before calling the logic to free memory used for the page table.
This results in IOMMU page table memory leak, and can be observed
when launching VM w/ pass-through devices.
Fix by freeing the memory used for page table before updating the mode.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.16.14-1 (bookworm) | linux 5.16.14-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= e42ba0633064ef23eb1c8c21edf96bac1541bd4b < 378e2fe1eb58d5c2ed55c8fe5e11f9db5033cdd6 | 378e2fe1eb58d5c2ed55c8fe5e11f9db5033cdd6 |
| linux | linux | >= e42ba0633064ef23eb1c8c21edf96bac1541bd4b < c78627f757e37c2cf386b59c700c4e1574988597 | c78627f757e37c2cf386b59c700c4e1574988597 |
| linux | linux | >= e42ba0633064ef23eb1c8c21edf96bac1541bd4b < 6b0b2d9a6a308bcd9300c2d83000a82812c56cea | 6b0b2d9a6a308bcd9300c2d83000a82812c56cea |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.16.14-1 | 5.16.14-1 |
| linux | linux_kernel | >= 0 < 5.16.14-1 | 5.16.14-1 |
| linux | linux_kernel | >= 0 < 5.16.14-1 | 5.16.14-1 |
| linux | linux_kernel | >= 5.12 < 5.15.27 | 5.15.27 |
| linux | linux_kernel | >= 5.16 < 5.16.13 | 5.16.13 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2022-48904: In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Fix I/O page table memory leak The current logic updates the I/O page t
osv·2024-08-22·CVSS 5.5
CVE-2022-48904 [MEDIUM] CVE-2022-48904: In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Fix I/O page table memory leak The current logic updates the I/O page t
In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Fix I/O page table memory leak The current logic updates the I/O page table mode for the domain before calling the logic to free memory used for the page table. This results in IOMMU page table memory leak, and can be observed when launching VM w/ pass-through devices. Fix by freeing the memory used for page table before updating the mode.
GHSA
GHSA-qm4j-q6jh-qw3p: In the Linux kernel, the following vulnerability has been resolved:
iommu/amd: Fix I/O page table memory leak
The current logic updates the I/O page
ghsa_unreviewed·2024-08-22
CVE-2022-48904 [MEDIUM] CWE-401 GHSA-qm4j-q6jh-qw3p: In the Linux kernel, the following vulnerability has been resolved:
iommu/amd: Fix I/O page table memory leak
The current logic updates the I/O page
In the Linux kernel, the following vulnerability has been resolved:
iommu/amd: Fix I/O page table memory leak
The current logic updates the I/O page table mode for the domain
before calling the logic to free memory used for the page table.
This results in IOMMU page table memory leak, and can be observed
when launching VM w/ pass-through devices.
Fix by freeing the memory used for page table before updating the mode.
Red Hat
kernel: iommu/amd: Fix I/O page table memory leak
vendor_redhat·2024-08-22·CVSS 5.5
CVE-2022-48904 [MEDIUM] CWE-401 kernel: iommu/amd: Fix I/O page table memory leak
kernel: iommu/amd: Fix I/O page table memory leak
In the Linux kernel, the following vulnerability has been resolved:
iommu/amd: Fix I/O page table memory leak
The current logic updates the I/O page table mode for the domain
before calling the logic to free memory used for the page table.
This results in IOMMU page table memory leak, and can be observed
when launching VM w/ pass-through devices.
Fix by freeing the memory used for page table before updating the mode.
Statement: This issue is fixed in RHEL-8.6 and above (including RHEL 8.10)
~~~
in (rhel-8.6, rhel-8.7, rhel-8.8, rhel-8.9, rhel-8.10) iommu/amd: Fix I/O page table memory leak
~~~
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red
Debian
CVE-2022-48904: linux - In the Linux kernel, the following vulnerability has been resolved: iommu/amd: ...
vendor_debian·2022·CVSS 5.5
CVE-2022-48904 [MEDIUM] CVE-2022-48904: linux - In the Linux kernel, the following vulnerability has been resolved: iommu/amd: ...
In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Fix I/O page table memory leak The current logic updates the I/O page table mode for the domain before calling the logic to free memory used for the page table. This results in IOMMU page table memory leak, and can be observed when launching VM w/ pass-through devices. Fix by freeing the memory used for page table before updating the mode.
Scope: local
bookworm: resolved (fixed in 5.16.14-1)
bullseye: resolved
forky: resolved (fixed in 5.16.14-1)
sid: resolved (fixed in 5.16.14-1)
trixie: resolved (fixed in 5.16.14-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-08-22
Published