CVE-2022-26364
x86 pv: Insufficient care with non-coherent mappings T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Xen maintains a type reference count for pages, in addition to a regular reference count. This scheme is used to maintain invariants required for Xen's safety, e.g. PV guests may not have direct writeable access to pagetables; updates need auditing by Xen. Unfortunately, Xen's safety logic doesn't account for CPU-induced cache non-coherency; cases where the CPU can cause the content of the cache to be different to the content in main memory. In such cases, Xen's safety logic can incorrectly conclude that the contents of a page is safe.
EPSS 0.11% · 28.7th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| fedoraproject | fedora | 35, 36 |
| xen | xen | |
| debian | debian_linux | 11.0 |
| Xen | xen | * |
Timeline
- Jun 9, 2022 CVE Published
- Jun 10, 2022 EPSS Score
- Jul 7, 2022 PoC Published
- Jul 29, 2022 EPSS Score
- Sep 15, 2022 EPSS Score
- Nov 3, 2022 EPSS Score
- Dec 21, 2022 EPSS Score
- Feb 7, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Mar 27, 2023 EPSS Score
- May 14, 2023 EPSS Score
- Jul 1, 2023 EPSS Score
References
- https://xenbits.xenproject.org/xsa/advisory-402.txt url
- http://xenbits.xen.org/xsa/advisory-402.html url
- [oss-security] 20220609 Xen Security Advisory 402 v4 (CVE-2022-26363,CVE-2022-26364) - x86 pv: Insufficient care with non-coherent mappings mailing-list
- FEDORA-2022-0142d562ca vendor-advisory
- http://packetstormsecurity.com/files/167710/Xen-PV-Guest-Non-SELFSNOOP-CPU-Memory-Corruption.html url
- DSA-5184 vendor-advisory
- FEDORA-2022-2c9f8224f8 vendor-advisory
- GLSA-202208-23 vendor-advisory
- https://xenbits.xen.org/xsa/advisory-402.html advisory
- https://xenbits.xen.org/xsa/advisory-401.html advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-26364 advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OH65U6FTTB5MLH5A6Q3TW7KVCGOG4MYI url
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RKRXZ4LHGCGMOG24ZCEJNY6R2BTS4S2Q url