UBUNTU-CVE-2022-42329
Dashboard / Vulnerabilities / UBUNTU-CVE-2022-42329
UBUNTU-CVE-2022-42329
Summary:
Details: Guests can trigger deadlock in Linux netback driver T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The patch for XSA-392 introduced another issue which might result in a deadlock when trying to free the SKB of a packet dropped due to the XSA-392 handling (CVE-2022-42328). Additionally when dropping packages for other reasons the same deadlock could occur in case of netpoll being active for the interface the xen-netback driver is connected to (CVE-2022-42329).
References: https://ubuntu.com/security/CVE-2022-42329, https://xenbits.xen.org/xsa/advisory-424.html, https://git.kernel.org/linus/74e7e1efdad45580cc3839f2a155174cf158f9b5, https://xenbits.xenproject.org/xsa/advisory-424.txt, https://ubuntu.com/security/notices/USN-5912-1, https://ubuntu.com/security/notices/USN-5917-1, https://ubuntu.com/security/notices/USN-5919-1, https://ubuntu.com/security/notices/USN-5920-1, https://ubuntu.com/security/notices/USN-5924-1, https://ubuntu.com/security/notices/USN-5925-1, https://ubuntu.com/security/notices/USN-5927-1, https://ubuntu.com/security/notices/USN-5934-1, https://ubuntu.com/security/notices/USN-5935-1, https://ubuntu.com/security/notices/USN-5938-1, https://ubuntu.com/security/notices/USN-5939-1, https://ubuntu.com/security/notices/USN-5940-1, https://ubuntu.com/security/notices/USN-5941-1, https://ubuntu.com/security/notices/USN-5951-1, https://ubuntu.com/security/notices/USN-5962-1, https://ubuntu.com/security/notices/USN-5970-1, https://ubuntu.com/security/notices/USN-5975-1, https://ubuntu.com/security/notices/USN-5979-1, https://ubuntu.com/security/notices/USN-6000-1, https://ubuntu.com/security/notices/USN-6007-1, https://www.cve.org/CVERecord?id=CVE-2022-42329
Affected packages
Package
Name: linux-azure
Purl: pkg:deb/ubuntu/linux-azure?arch=source&distro=trusty%2Fesm
Affected ranges
Type: ECOSYSTEM
Events:
