xen: CVE-2022-42335 (XSA-430)

Related Vulnerabilities: CVE-2022-42335  

Debian Bug report logs - #1034842
xen: CVE-2022-42335 (XSA-430)

version graph

Reported by: Salvatore Bonaccorso <carnil@debian.org>

Date: Tue, 25 Apr 2023 18:57:07 UTC

Severity: grave

Tags: security, upstream

Found in version xen/4.17.0+74-g3eac216e6e-1

Reply or subscribe to this bug.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, carnil@debian.org, team@security.debian.org, Debian Xen Team <pkg-xen-devel@lists.alioth.debian.org>:
Bug#1034842; Package src:xen. (Tue, 25 Apr 2023 18:57:09 GMT) (full text, mbox, link).


Acknowledgement sent to Salvatore Bonaccorso <carnil@debian.org>:
New Bug report received and forwarded. Copy sent to carnil@debian.org, team@security.debian.org, Debian Xen Team <pkg-xen-devel@lists.alioth.debian.org>. (Tue, 25 Apr 2023 18:57:09 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Salvatore Bonaccorso <carnil@debian.org>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: xen: CVE-2022-42335 (XSA-430)
Date: Tue, 25 Apr 2023 20:55:58 +0200
Source: xen
Version: 4.17.0+74-g3eac216e6e-1
Severity: grave
Tags: security upstream
Justification: user security hole
X-Debbugs-Cc: carnil@debian.org, Debian Security Team <team@security.debian.org>

Hi,

The following vulnerability was published for xen, affects only 4.17.

Filling as RC, to make it on the radar for the bookworm release (and
make IMHO sense to try to get it in before release).

CVE-2022-42335[0]:
| x86 shadow paging arbitrary pointer dereference In environments where
| host assisted address translation is necessary but Hardware Assisted
| Paging (HAP) is unavailable, Xen will run guests in so called shadow
| mode. Due to too lax a check in one of the hypervisor routines used
| for shadow page handling it is possible for a guest with a PCI device
| passed through to cause the hypervisor to access an arbitrary pointer
| partially under guest control.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2022-42335
    https://www.cve.org/CVERecord?id=CVE-2022-42335
[1] https://www.openwall.com/lists/oss-security/2023/04/25/1
[2] https://xenbits.xen.org/xsa/advisory-430.html

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore



Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Wed Apr 26 13:12:44 2023; Machine Name: buxtehude

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.