Логотип exploitDog
bind:CVE-2022-23042
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-23042

Количество 19

Количество 19

ubuntu логотип

CVE-2022-23042

больше 3 лет назад

Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Several Linux PV device frontends are using the grant table interfaces for removing access rights of the backends in ways being subject to race conditions, resulting in potential data leaks, data corruption by malicious backends, and denial of service triggered by malicious backends: blkfront, netfront, scsifront and the gntalloc driver are testing whether a grant reference is still in use. If this is not the case, they assume that a following removal of the granted access will always succeed, which is not true in case the backend has mapped the granted page between those two operations. As a result the backend can keep access to the memory page of the guest no matter how the page will be used after the frontend I/O has finished. The xenbus driver has a similar problem, as it doesn't check the suc...

CVSS3: 7
EPSS: Низкий
nvd логотип

CVE-2022-23042

больше 3 лет назад

Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Several Linux PV device frontends are using the grant table interfaces for removing access rights of the backends in ways being subject to race conditions, resulting in potential data leaks, data corruption by malicious backends, and denial of service triggered by malicious backends: blkfront, netfront, scsifront and the gntalloc driver are testing whether a grant reference is still in use. If this is not the case, they assume that a following removal of the granted access will always succeed, which is not true in case the backend has mapped the granted page between those two operations. As a result the backend can keep access to the memory page of the guest no matter how the page will be used after the frontend I/O has finished. The xenbus driver has a similar problem, as it doesn't check the succes

CVSS3: 7
EPSS: Низкий
debian логотип

CVE-2022-23042

больше 3 лет назад

Linux PV device frontends vulnerable to attacks by backends T[his CNA ...

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-vg9g-89fh-g3hw

больше 3 лет назад

Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Several Linux PV device frontends are using the grant table interfaces for removing access rights of the backends in ways being subject to race conditions, resulting in potential data leaks, data corruption by malicious backends, and denial of service triggered by malicious backends: blkfront, netfront, scsifront and the gntalloc driver are testing whether a grant reference is still in use. If this is not the case, they assume that a following removal of the granted access will always succeed, which is not true in case the backend has mapped the granted page between those two operations. As a result the backend can keep access to the memory page of the guest no matter how the page will be used after the frontend I/O has finished. The xenbus driver has a similar problem, as it doesn't check the suc...

CVSS3: 7
EPSS: Низкий
fstec логотип

BDU:2022-05400

больше 3 лет назад

Уязвимость утилиты гипервизора Xen, вызванная ошибками синхронизации при использовании общего ресурса, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7
EPSS: Низкий
oracle-oval логотип

ELSA-2022-9480

около 3 лет назад

ELSA-2022-9480: Unbreakable Enterprise kernel-container security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2022-9479

около 3 лет назад

ELSA-2022-9479: Unbreakable Enterprise kernel security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:1283-1

около 3 лет назад

Security update for the Linux Kernel

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:1270-1

около 3 лет назад

Security update for the Linux Kernel

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:1256-1

около 3 лет назад

Security update for the Linux Kernel

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:1402-1

около 3 лет назад

Security update for the Linux Kernel

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:1267-1

около 3 лет назад

Security update for the Linux Kernel

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:1266-1

около 3 лет назад

Security update for the Linux Kernel

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:1255-1

около 3 лет назад

Security update for the Linux Kernel

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:1197-1

около 3 лет назад

Security update for the Linux Kernel

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2022:1039-1

около 3 лет назад

Security update for the Linux Kernel

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:1196-1

около 3 лет назад

Security update for the Linux Kernel

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:1039-1

около 3 лет назад

Security update for the Linux Kernel

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:1163-1

около 3 лет назад

Security update for the Linux Kernel

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2022-23042

Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Several Linux PV device frontends are using the grant table interfaces for removing access rights of the backends in ways being subject to race conditions, resulting in potential data leaks, data corruption by malicious backends, and denial of service triggered by malicious backends: blkfront, netfront, scsifront and the gntalloc driver are testing whether a grant reference is still in use. If this is not the case, they assume that a following removal of the granted access will always succeed, which is not true in case the backend has mapped the granted page between those two operations. As a result the backend can keep access to the memory page of the guest no matter how the page will be used after the frontend I/O has finished. The xenbus driver has a similar problem, as it doesn't check the suc...

CVSS3: 7
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-23042

Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Several Linux PV device frontends are using the grant table interfaces for removing access rights of the backends in ways being subject to race conditions, resulting in potential data leaks, data corruption by malicious backends, and denial of service triggered by malicious backends: blkfront, netfront, scsifront and the gntalloc driver are testing whether a grant reference is still in use. If this is not the case, they assume that a following removal of the granted access will always succeed, which is not true in case the backend has mapped the granted page between those two operations. As a result the backend can keep access to the memory page of the guest no matter how the page will be used after the frontend I/O has finished. The xenbus driver has a similar problem, as it doesn't check the succes

CVSS3: 7
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-23042

Linux PV device frontends vulnerable to attacks by backends T[his CNA ...

CVSS3: 7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-vg9g-89fh-g3hw

Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Several Linux PV device frontends are using the grant table interfaces for removing access rights of the backends in ways being subject to race conditions, resulting in potential data leaks, data corruption by malicious backends, and denial of service triggered by malicious backends: blkfront, netfront, scsifront and the gntalloc driver are testing whether a grant reference is still in use. If this is not the case, they assume that a following removal of the granted access will always succeed, which is not true in case the backend has mapped the granted page between those two operations. As a result the backend can keep access to the memory page of the guest no matter how the page will be used after the frontend I/O has finished. The xenbus driver has a similar problem, as it doesn't check the suc...

CVSS3: 7
0%
Низкий
больше 3 лет назад
fstec логотип
BDU:2022-05400

Уязвимость утилиты гипервизора Xen, вызванная ошибками синхронизации при использовании общего ресурса, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7
0%
Низкий
больше 3 лет назад
oracle-oval логотип
ELSA-2022-9480

ELSA-2022-9480: Unbreakable Enterprise kernel-container security update (IMPORTANT)

около 3 лет назад
oracle-oval логотип
ELSA-2022-9479

ELSA-2022-9479: Unbreakable Enterprise kernel security update (IMPORTANT)

около 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:1283-1

Security update for the Linux Kernel

около 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:1270-1

Security update for the Linux Kernel

около 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:1256-1

Security update for the Linux Kernel

около 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:1402-1

Security update for the Linux Kernel

около 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:1267-1

Security update for the Linux Kernel

около 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:1266-1

Security update for the Linux Kernel

около 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:1255-1

Security update for the Linux Kernel

около 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:1197-1

Security update for the Linux Kernel

около 3 лет назад
suse-cvrf логотип
openSUSE-SU-2022:1039-1

Security update for the Linux Kernel

около 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:1196-1

Security update for the Linux Kernel

около 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:1039-1

Security update for the Linux Kernel

около 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:1163-1

Security update for the Linux Kernel

около 3 лет назад

Уязвимостей на страницу