Description
Linux disk/nic frontends data leaks T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Linux Block and Network PV device frontends don't zero memory regions before sharing them with the backend (CVE-2022-26365, CVE-2022-33740). Additionally the granularity of the grant table doesn't allow sharing less than a 4K page, leading to unrelated data residing in the same 4K page as data shared with a backend being accessible by such backend (CVE-2022-33741, CVE-2022-33742).
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3131-1 | linux security update |
Debian DSA |
DSA-5191-1 | linux security update |
EUVD |
EUVD-2022-30924 | Linux disk/nic frontends data leaks T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Linux Block and Network PV device frontends don't zero memory regions before sharing them with the backend (CVE-2022-26365, CVE-2022-33740). Additionally the granularity of the grant table doesn't allow sharing less than a 4K page, leading to unrelated data residing in the same 4K page as data shared with a backend being accessible by such backend (CVE-2022-33741, CVE-2022-33742). |
Ubuntu USN |
USN-5572-1 | Linux kernel (AWS) vulnerabilities |
Ubuntu USN |
USN-5572-2 | Linux kernel (AWS) vulnerabilities |
Ubuntu USN |
USN-5579-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-5623-1 | Linux kernel (HWE) vulnerabilities |
Ubuntu USN |
USN-5624-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-5633-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-5635-1 | Linux kernel (GKE) vulnerabilities |
Ubuntu USN |
USN-5640-1 | Linux kernel (Oracle) vulnerabilities |
Ubuntu USN |
USN-5644-1 | Linux kernel (GCP) vulnerabilities |
Ubuntu USN |
USN-5648-1 | Linux kernel (GKE) vulnerabilities |
Ubuntu USN |
USN-5655-1 | Linux kernel (Intel IoTG) vulnerabilities |
Ubuntu USN |
USN-5668-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-5669-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-5669-2 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-5677-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-5678-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-5679-1 | Linux kernel (HWE) vulnerabilities |
Ubuntu USN |
USN-5682-1 | Linux kernel (AWS) vulnerabilities |
Ubuntu USN |
USN-5683-1 | Linux kernel (IBM) vulnerabilities |
Ubuntu USN |
USN-5684-1 | Linux kernel (Azure) vulnerabilities |
Ubuntu USN |
USN-5687-1 | Linux kernel (Azure) vulnerabilities |
Ubuntu USN |
USN-5695-1 | Linux kernel (GCP) vulnerabilities |
Ubuntu USN |
USN-5706-1 | Linux kernel (Azure CVM) vulnerabilities |
Ubuntu USN |
USN-5773-1 | Linux kernel (OEM) vulnerabilities |
Ubuntu USN |
USN-5789-1 | Linux kernel (OEM) vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: XEN
Published:
Updated: 2024-08-03T05:03:32.784Z
Reserved: 2022-03-02T00:00:00.000Z
Link: CVE-2022-26365
No data.
Status : Modified
Published: 2022-07-05T13:15:08.270
Modified: 2024-11-21T06:53:50.423
Link: CVE-2022-26365
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
Debian DSA
EUVD
Ubuntu USN