Lucene search

K
prionPRIOn knowledge basePRION:CVE-2022-42328
HistoryDec 07, 2022 - 1:15 a.m.

Design/Logic Flaw

2022-12-0701:15:00
PRIOn knowledge base
www.prio-n.com
11
linux netback driver
deadlock
patch xsa-392
cve-2022-42328
netpoll
xen-netback driver

6.2 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

27.7%

Guests can trigger deadlock in Linux netback driver T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The patch for XSA-392 introduced another issue which might result in a deadlock when trying to free the SKB of a packet dropped due to the XSA-392 handling (CVE-2022-42328). Additionally when dropping packages for other reasons the same deadlock could occur in case of netpoll being active for the interface the xen-netback driver is connected to (CVE-2022-42329).

CPENameOperatorVersion
debian_linuxeq10.0
linux_kernellt6.0