← Back

CVE-2022-26365

nvd nist
Published: Jul 5, 2022Modified: Nov 21, 2024

JSON object

Loading...
7.1
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Exploitability: 1.8 / Impact: 5.2
Source: NVD

Description

Linux disk/nic frontends data leaks T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Linux Block and Network PV device frontends don't zero memory regions before sharing them with the backend (CVE-2022-26365, CVE-2022-33740). Additionally the granularity of the grant table doesn't allow sharing less than a 4K page, leading to unrelated data residing in the same 4K page as data shared with a backend being accessible by such backend (CVE-2022-33741, CVE-2022-33742).

Affected (22)

Products: Linux: Linux Kernel · Xen: Xen · Debian: Debian Linux · +1 more
Show all products
1 product
Linux Kernel
1 product
Xen
1 product
Debian Linux
1 product
Fedora
Configuration A
18 vulnerable
Vulnerable SoftwareAffected Versions
Linux
From 2.6.13 to 4.9.322
From 4.14 to 4.14.287
From 4.19 to 4.19.251
From 5.10 to 5.10.129
From 5.15 to 5.15.53
From 5.18 to 5.18.10
From 5.4 to 5.4.204
Version 2.6.12 rc2
Version 2.6.12 rc3
Version 2.6.12 rc4
Version 2.6.12 rc5
Version 2.6.12 rc6
Version 5.19 rc1
Version 5.19 rc2
Version 5.19 rc3
Version 5.19 rc4
Version 5.19 rc5
All versions
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Debian
Version 10.0
Version 11.0
Configuration C
2 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 35
Version 36

References (14)

Source: security@xen.org
Mailing ListPatchThird Party Advisory
Source: security@xen.org
PatchVendor Advisory
Source: security@xen.org
Mailing ListThird Party Advisory
Source: security@xen.org
Third Party Advisory
Source: security@xen.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.