VDB

DEBIAN-CVE-2022-33745

DEBIAN-CVE-2022-33745 PUBLISHED CVSS 8.800000190734863 HIGH

insufficient TLB flush for x86 PV guests in shadow mode For migration as well as to work around kernels unaware of L1TF (see XSA-273), PV guests may be run in shadow paging mode. To address XSA-401, code was moved inside a function in Xen. This code movement missed a variable changing meaning / value between old and new code positions. The now wrong use of the variable did lead to a wrong TLB flush condition, omitting flushes where such are necessary.

Risk Scores

CVSS 3.1
8.800000190734863
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersions
Debian:11xen*, *, 0
Debian:14xen0, 0, 0
Debian:12xen0, 0, 0
Debian:13xen0, 0, 0

Timeline

  • Jul 26, 2022 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›