5.6
CVSSv3

CVE-2022-33748

Published: 11/10/2022 Updated: 04/02/2024
CVSS v3 Base Score: 5.6 | Impact Score: 4 | Exploitability Score: 1.1
VMScore: 0

Vulnerability Summary

lock order inversion in transitive grant copy handling As part of XSA-226 a missing cleanup call was inserted on an error handling path. While doing so, locking requirements were not paid attention to. As a result two cooperating guests granting each other transitive grants can cause locks to be acquired nested within one another, but in respectively opposite order. With suitable timing between the involved grant copy operations this may result in the locking up of a CPU.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

xen xen

fedoraproject fedora 35

fedoraproject fedora 36

fedoraproject fedora 37

debian debian linux 11.0

Vendor Advisories

Debian Bug report logs - #1021668 xen: CVE-2022-33749 CVE-2022-33748 CVE-2022-33747 CVE-2022-33746 Package: src:xen; Maintainer for src:xen is Debian Xen Team <pkg-xen-devel@listsaliothdebianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Wed, 12 Oct 2022 17:39:02 UTC Severity: important Tags: securit ...
Multiple vulnerabilities have been discovered in the Xen hypervisor, which could result in privilege escalation, denial of service or information leaks For the stable distribution (bullseye), these problems have been fixed in version 4145+86-g1c354767d5-1 We recommend that you upgrade your xen packages For the detailed security status of xen p ...