Logo
vulnerabilityCVE-2022-33747
Name
CVE-2022-33747
Source
NVD ( link)Debian ( link)
Description
Arm: unbounded memory consumption for 2nd-level page tables Certain actions require e.g. removing pages from a guest's P2M (Physical-to-Machine) mapping. When large pages are in use to map guest pages in the 2nd-stage page tables, such a removal operation may incur a memory allocation (to replace a large mapping with individual smaller ones). These memory allocations are taken from the global memory pool. A malicious guest might be able to cause the global memory pool to be exhausted by manipulating its own P2M mappings.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
xen
Exploitable

Vulnerability Rating#


3.8
CVSSv31

Others affected component#


Name
Project
Project Version
Version
Status
buildroot
master
4.19.5
Exploitable