Database/Kernel, userspace & hypervisor

Xen (shadow paging): x86 shadow plus log-dirty mode use-after-free - guest to host
CVSS 7.8CVE-2022-42332Kernel, userspace & hypervisorXSA-427curated
Impact
x86 shadow plus log-dirty mode use-after-free - guest to host
Who can reach it
Tenant VM guest
What to do
Hypervisor patch + reboot/evacuation. Shadow paging is used during live migration, so this is reachable in normal operations
References
Related entries
- Xen (shadow paging): x86 shadow paging arbitrary pointer dereference - host crash or worseCVE-2022-42335 · Xen (shadow paging)Unscored
- Linux i915 GPU kernel driver: A use-after-free in the i915 GPU kernel driver. The general shape is that a GPU object isCVE-2022-48662 · Linux i915 GPU kernel driverHigh
- Linux kernel (net/smc): An unprivileged tenant that opens an AF_SMC socket, registers it with epoll, and lets theCVE-2022-48721 · Linux kernel (net/smc)High
- Linux kernel (drivers/gpu/drm/vmwgfx): When the copy of the fence reply back to userspace fails, the driver installs aCVE-2022-48771 · Linux kernel (drivers/gpu/drm/vmwgfx)High
- Linux kernel (drivers/gpu/drm/vmwgfx): User-resource lookup during command submission used a broken RCU fast path, soCVE-2022-48887 · Linux kernel (drivers/gpu/drm/vmwgfx)High
- Linux kernel (drivers/gpu/drm/virtio): GEM handle values are guessable, and the driver dereferences the buffer objectCVE-2022-48899 · Linux kernel (drivers/gpu/drm/virtio)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.