UBUNTU-CVE-2022-26357
Dashboard / Vulnerabilities / UBUNTU-CVE-2022-26357
Summary:
Details: race in VT-d domain ID cleanup Xen domain IDs are up to 15 bits wide. VT-d hardware may allow for only less than 15 bits to hold a domain ID associating a physical device with a particular domain. Therefore internally Xen domain IDs are mapped to the smaller value range. The cleaning up of the housekeeping structures has a race, allowing for VT-d domain IDs to be leaked and flushes to be bypassed.
References: https://ubuntu.com/security/CVE-2022-26357, https://xenbits.xen.org/xsa/advisory-399.html, https://xenbits.xenproject.org/xsa/advisory-399.txt, http://xenbits.xen.org/xsa/advisory-399.html, http://www.openwall.com/lists/oss-security/2022/04/05/2, https://www.cve.org/CVERecord?id=CVE-2022-26357
Affected packages
Package
Name: xen
Purl: pkg:deb/ubuntu/xen?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
