Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-49660

Опубликовано: 26 фев. 2025
Источник: redhat
CVSS3: 5.5

Описание

[REJECTED CVE] A vulnerability was identified in the Linux kernel’s Xen ARM implementation, where a race condition in RB-tree-based P2M (physical-to-machine) accounting could occur due to an unprotected read of the tree root in __set_phys_to_machine_multi(). An attacker could theoretically exploit this by triggering concurrent grant table operations (via gnttab_map_refs() and gnttab_unmap_refs()) that lead to incorrect or inconsistent memory mappings, potentially causing memory corruption or denial of service. However, due to the extremely rare occurrence and limited impact in real-world use

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10kernelNot affected
Red Hat Enterprise Linux 6kernelNot affected
Red Hat Enterprise Linux 7kernelNot affected
Red Hat Enterprise Linux 7kernel-rtNot affected
Red Hat Enterprise Linux 8kernelOut of support scope
Red Hat Enterprise Linux 8kernel-rtOut of support scope
Red Hat Enterprise Linux 9kernelWill not fix
Red Hat Enterprise Linux 9kernel-rtWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=2348318kernel: xen/arm: Fix race in RB-tree based P2M accounting

5.5 Medium

CVSS3

Связанные уязвимости

nvd
12 месяцев назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

5.5 Medium

CVSS3