CVE-2023-46837
published 2024-01-05CVE-2023-46837: Arm provides multiple helpers to clean & invalidate the cache for a given region. This is, for instance, used when allocating guest memory to ensure any writes…
PriorityP411low3.3CVSS 3.1
AVLACLPRLUINSUCLINAN
EPSS
0.24%
15.1th percentile
Arm provides multiple helpers to clean & invalidate the cache
for a given region. This is, for instance, used when allocating
guest memory to ensure any writes (such as the ones during scrubbing)
have reached memory before handing over the page to a guest.
Unfortunately, the arithmetics in the helpers can overflow and would
then result to skip the cache cleaning/invalidation. Therefore there
is no guarantee when all the writes will reach the memory.
This undefined behavior was meant to be addressed by XSA-437, but the
approach was not sufficient.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xen | < xen 4.17.3+10-g091466ba55-1~deb12u1 (bookworm) | xen 4.17.3+10-g091466ba55-1~deb12u1 (bookworm) |
| xen | xen | <= 4.16 | — |
| xen | xen | >= 0 < 4.16.5-r5 | 4.16.5-r5 |
| xen | xen | >= 0 < 4.16.5-r5 | 4.16.5-r5 |
| xen | xen | >= 0 < 4.17.2-r5 | 4.17.2-r5 |
| xen | xen | >= 0 < 4.18.0-r2 | 4.18.0-r2 |
| xen | xen | >= 0 < 4.18.0-r2 | 4.18.0-r2 |
| xen | xen | >= 0 < 4.18.0-r2 | 4.18.0-r2 |
| xen | xen | >= 0 < 4.18.0-r2 | 4.18.0-r2 |
| xen | xen | >= 0 < 4.18.0-r2 | 4.18.0-r2 |
| xen | xen | >= 0 < 4.17.3+10-g091466ba55-1~deb12u1 | 4.17.3+10-g091466ba55-1~deb12u1 |
| xen | xen | >= 0 < 4.17.3+10-g091466ba55-1 | 4.17.3+10-g091466ba55-1 |
| xen | xen | >= 0 < 4.17.3+10-g091466ba55-1 | 4.17.3+10-g091466ba55-1 |
CVSS provenance
nvdv3.13.3LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
osv3.3LOW
vendor_debian3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2023-46837: Arm provides multiple helpers to clean & invalidate the cache for a given region
osv·2024-01-05·CVSS 3.3
CVE-2023-46837 [LOW] CVE-2023-46837: Arm provides multiple helpers to clean & invalidate the cache for a given region
Arm provides multiple helpers to clean & invalidate the cache for a given region. This is, for instance, used when allocating guest memory to ensure any writes (such as the ones during scrubbing) have reached memory before handing over the page to a guest. Unfortunately, the arithmetics in the helpers can overflow and would then result to skip the cache cleaning/invalidation. Therefore there is no guarantee when all the writes will reach the memory. This undefined behavior was meant to be addressed by XSA-437, but the approach was not sufficient.
GHSA
GHSA-v75r-qqcp-59c7: Arm provides multiple helpers to clean & invalidate the cache
for a given region
ghsa_unreviewed·2024-01-05
CVE-2023-46837 [LOW] CWE-119 GHSA-v75r-qqcp-59c7: Arm provides multiple helpers to clean & invalidate the cache
for a given region
Arm provides multiple helpers to clean & invalidate the cache
for a given region. This is, for instance, used when allocating
guest memory to ensure any writes (such as the ones during scrubbing)
have reached memory before handing over the page to a guest.
Unfortunately, the arithmetics in the helpers can overflow and would
then result to skip the cache cleaning/invalidation. Therefore there
is no guarantee when all the writes will reach the memory.
This undefined behavior was meant to be addressed by XSA-437, but the
approach was not sufficient.
OSV
CVE-2023-46837: Arm provides multiple helpers to clean & invalidate the cache
for a given region
osv·2024-01-05·CVSS 3.3
CVE-2023-46837 [LOW] CVE-2023-46837: Arm provides multiple helpers to clean & invalidate the cache
for a given region
Arm provides multiple helpers to clean & invalidate the cache
for a given region. This is, for instance, used when allocating
guest memory to ensure any writes (such as the ones during scrubbing)
have reached memory before handing over the page to a guest.
Unfortunately, the arithmetics in the helpers can overflow and would
then result to skip the cache cleaning/invalidation. Therefore there
is no guarantee when all the writes will reach the memory.
This undefined behavior was meant to be addressed by XSA-437, but the
approach was not sufficient.
Debian
CVE-2023-46837: xen - Arm provides multiple helpers to clean & invalidate the cache for a given region...
vendor_debian·2023·CVSS 3.3
CVE-2023-46837 [LOW] CVE-2023-46837: xen - Arm provides multiple helpers to clean & invalidate the cache for a given region...
Arm provides multiple helpers to clean & invalidate the cache for a given region. This is, for instance, used when allocating guest memory to ensure any writes (such as the ones during scrubbing) have reached memory before handing over the page to a guest. Unfortunately, the arithmetics in the helpers can overflow and would then result to skip the cache cleaning/invalidation. Therefore there is no guarantee when all the writes will reach the memory. This undefined behavior was meant to be addressed by XSA-437, but the approach was not sufficient.
Scope: local
bookworm: resolved (fixed in 4.17.3+10-g091466ba55-1~deb12u1)
bullseye: open
forky: resolved (fixed in 4.17.3+10-g091466ba55-1)
sid: resolved (fixed in 4.17.3+10-g091466ba55-1)
trixie: resolved (fixed in 4.17.3+10-g091466ba55-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://lists.fedoraproject.org/archives/list/[email protected]/message/JFVKWYQFRUU3CAS53THTUKXEOUDWI42G/https://lists.fedoraproject.org/archives/list/[email protected]/message/XLL6SQ6IKFYXLYWITYZCRV5IBRK5G35R/https://xenbits.xenproject.org/xsa/advisory-447.htmlhttp://xenbits.xen.org/xsa/advisory-447.htmlhttps://lists.fedoraproject.org/archives/list/[email protected]/message/JFVKWYQFRUU3CAS53THTUKXEOUDWI42G/https://lists.fedoraproject.org/archives/list/[email protected]/message/XLL6SQ6IKFYXLYWITYZCRV5IBRK5G35R/https://xenbits.xenproject.org/xsa/advisory-447.html
2024-01-05
Published