Database/Kernel, userspace & hypervisor

Xen (x86): Unintended memory sharing between guests - cross-tenant data exposure
CVSS 7.1CVE-2022-42327Kernel, userspace & hypervisorXSA-412curated
Impact
Unintended memory sharing between guests - cross-tenant data exposure
Who can reach it
Tenant VM guest
What to do
Hypervisor patch + evacuation/reboot. Direct multi-tenant isolation break
References
Related entries
- Xen (x86): CPU opcode cache corruption - host instability triggerable from a guestCVE-2025-54518 · Xen (x86)High
- Linux kernel (arch/x86/kvm): A guest that is not advertised long mode makes the host's SMM emulator walk 16CVE-2022-49883 · Linux kernel (arch/x86/kvm)High
- Linux kernel (drivers/vfio/pci/hisilicon): The VFIO migration save and resume paths do not advance the data pointer byCVE-2023-52453 · Linux kernel (drivers/vfio/pci/hisilicon)High
- Linux kernel (drivers/gpu/drm/vmwgfx): A tenant that asks for a fence event on its DRM fd and then reads the fd backCVE-2024-36960 · Linux kernel (drivers/gpu/drm/vmwgfx)High
- Linux kernel (drivers/iommu/iommufd): A tenant supplies an IOVA and user pointer whose alignment math overflows, soCVE-2024-47719 · Linux kernel (drivers/iommu/iommufd)High
- Linux kernel (ALSA usb-audio): Out-of-bounds read finding clock sourcesCVE-2024-53150 · Linux kernel (ALSA usb-audio)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.