Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-26357

Опубликовано: 05 апр. 2022
Источник: nvd
CVSS3: 7
CVSS2: 6.2
EPSS Низкий

Описание

race in VT-d domain ID cleanup Xen domain IDs are up to 15 bits wide. VT-d hardware may allow for only less than 15 bits to hold a domain ID associating a physical device with a particular domain. Therefore internally Xen domain IDs are mapped to the smaller value range. The cleaning up of the housekeeping structures has a race, allowing for VT-d domain IDs to be leaked and flushes to be bypassed.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:o:xen:xen:*:*:*:*:*:*:*:*
Версия от 4.11.0 (включая) до 4.12.0 (исключая)
cpe:2.3:o:xen:xen:*:*:*:*:*:*:*:*
Версия от 4.13.0 (включая) до 4.16.0 (исключая)
Конфигурация 2
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
Конфигурация 3

Одно из

cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*

EPSS

Процентиль: 5%
0.0002
Низкий

7 High

CVSS3

6.2 Medium

CVSS2

Дефекты

CWE-362

Связанные уязвимости

CVSS3: 7
ubuntu
почти 4 года назад

race in VT-d domain ID cleanup Xen domain IDs are up to 15 bits wide. VT-d hardware may allow for only less than 15 bits to hold a domain ID associating a physical device with a particular domain. Therefore internally Xen domain IDs are mapped to the smaller value range. The cleaning up of the housekeeping structures has a race, allowing for VT-d domain IDs to be leaked and flushes to be bypassed.

CVSS3: 7
debian
почти 4 года назад

race in VT-d domain ID cleanup Xen domain IDs are up to 15 bits wide. ...

CVSS3: 7
github
почти 4 года назад

race in VT-d domain ID cleanup Xen domain IDs are up to 15 bits wide. VT-d hardware may allow for only less than 15 bits to hold a domain ID associating a physical device with a particular domain. Therefore internally Xen domain IDs are mapped to the smaller value range. The cleaning up of the housekeeping structures has a race, allowing for VT-d domain IDs to be leaked and flushes to be bypassed.

suse-cvrf
почти 4 года назад

Security update for xen

suse-cvrf
почти 4 года назад

Security update for xen

EPSS

Процентиль: 5%
0.0002
Низкий

7 High

CVSS3

6.2 Medium

CVSS2

Дефекты

CWE-362