Vulnerability Description
Linux disk/nic frontends data leaks T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Linux Block and Network PV device frontends don't zero memory regions before sharing them with the backend (CVE-2022-26365, CVE-2022-33740). Additionally the granularity of the grant table doesn't allow sharing less than a 4K page, leading to unrelated data residing in the same 4K page as data shared with a backend being accessible by such backend (CVE-2022-33741, CVE-2022-33742).
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 2.6.13, < 4.9.322 |
| Xen | Xen | - |
| Debian | Debian Linux | 10.0 |
| Fedoraproject | Fedora | 35 |
Related Weaknesses (CWE)
References
- http://www.openwall.com/lists/oss-security/2022/07/05/6Mailing ListPatchThird Party Advisory
- http://xenbits.xen.org/xsa/advisory-403.htmlPatchVendor Advisory
- https://lists.debian.org/debian-lts-announce/2022/10/msg00000.htmlMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://www.debian.org/security/2022/dsa-5191Third Party Advisory
- https://xenbits.xenproject.org/xsa/advisory-403.txtVendor Advisory
- http://www.openwall.com/lists/oss-security/2022/07/05/6Mailing ListPatchThird Party Advisory
- http://xenbits.xen.org/xsa/advisory-403.htmlPatchVendor Advisory
- https://lists.debian.org/debian-lts-announce/2022/10/msg00000.htmlMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://www.debian.org/security/2022/dsa-5191Third Party Advisory
- https://xenbits.xenproject.org/xsa/advisory-403.txtVendor Advisory
FAQ
What is CVE-2022-26365?
CVE-2022-26365 is a vulnerability with a CVSS score of 7.1 (HIGH). Linux disk/nic frontends data leaks T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Linux Block and Network PV device f...
How severe is CVE-2022-26365?
CVE-2022-26365 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-26365?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Xen Xen, Debian Debian Linux, Fedoraproject Fedora.