UBUNTU-CVE-2022-33745
Dashboard / Vulnerabilities / UBUNTU-CVE-2022-33745
Summary:
Details: insufficient TLB flush for x86 PV guests in shadow mode For migration as well as to work around kernels unaware of L1TF (see XSA-273), PV guests may be run in shadow paging mode. To address XSA-401, code was moved inside a function in Xen. This code movement missed a variable changing meaning / value between old and new code positions. The now wrong use of the variable did lead to a wrong TLB flush condition, omitting flushes where such are necessary.
References: https://ubuntu.com/security/CVE-2022-33745, https://xenbits.xen.org/xsa/advisory-408.html, https://xenbits.xenproject.org/xsa/advisory-408.txt, http://xenbits.xen.org/xsa/advisory-408.html, http://www.openwall.com/lists/oss-security/2022/07/26/2, http://www.openwall.com/lists/oss-security/2022/07/26/3, https://www.cve.org/CVERecord?id=CVE-2022-33745
Affected packages
Package
Name: xen
Purl: pkg:deb/ubuntu/xen?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
