Lucene search

K
cvelistXENCVELIST:CVE-2022-33747
HistoryOct 11, 2022 - 12:00 a.m.

CVE-2022-33747

2022-10-1100:00:00
XEN
www.cve.org
2
arm
unbounded memory consumption
2nd-level page tables
large pages
memory allocation
global memory pool
malicious guest
p2m mappings

6.3 Medium

AI Score

Confidence

Low

0.0005 Low

EPSS

Percentile

18.1%

Arm: unbounded memory consumption for 2nd-level page tables Certain actions require e.g. removing pages from a guest’s P2M (Physical-to-Machine) mapping. When large pages are in use to map guest pages in the 2nd-stage page tables, such a removal operation may incur a memory allocation (to replace a large mapping with individual smaller ones). These memory allocations are taken from the global memory pool. A malicious guest might be able to cause the global memory pool to be exhausted by manipulating its own P2M mappings.

CNA Affected

[
  {
    "vendor": "Xen",
    "product": "xen",
    "versions": [
      {
        "version": "consult Xen advisory XSA-409",
        "status": "unknown"
      }
    ]
  }
]

6.3 Medium

AI Score

Confidence

Low

0.0005 Low

EPSS

Percentile

18.1%