Lucene search

K
cve[email protected]CVE-2022-42329
HistoryDec 07, 2022 - 1:15 a.m.

CVE-2022-42329

2022-12-0701:15:11
CWE-667
web.nvd.nist.gov
153
cve-2022-42329
linux netback driver
deadlock
xsa-392
skb
packet dropped

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

6.5 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

27.7%

Guests can trigger deadlock in Linux netback driver T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The patch for XSA-392 introduced another issue which might result in a deadlock when trying to free the SKB of a packet dropped due to the XSA-392 handling (CVE-2022-42328). Additionally when dropping packages for other reasons the same deadlock could occur in case of netpoll being active for the interface the xen-netback driver is connected to (CVE-2022-42329).

Affected configurations

NVD
Node
linuxlinux_kernelRange<6.0
Node
debiandebian_linuxMatch10.0

CNA Affected

[
  {
    "vendor": "Linux",
    "product": "Linux",
    "versions": [
      {
        "version": "consult Xen advisory XSA-424",
        "status": "unknown"
      }
    ]
  }
]

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

6.5 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

27.7%