Name | CVE-2022-33742 |
Description | Linux disk/nic frontends data leaks T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Linux Block and Network PV device frontends don't zero memory regions before sharing them with the backend (CVE-2022-26365, CVE-2022-33740). Additionally the granularity of the grant table doesn't allow sharing less than a 4K page, leading to unrelated data residing in the same 4K page as data shared with a backend being accessible by such backend (CVE-2022-33741, CVE-2022-33742). |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
References | DLA-3131-1, DSA-5191-1, ELA-661-1, ELA-696-1 |
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|
linux (PTS) | jessie, jessie (lts) | 3.16.84-1 | vulnerable |
| stretch (security) | 4.9.320-2 | vulnerable |
| stretch (lts), stretch | 4.9.320-3 | vulnerable |
| buster (security), buster, buster (lts) | 4.19.316-1 | fixed |
| bullseye (security), bullseye | 5.10.223-1 | fixed |
| bookworm | 6.1.106-3 | fixed |
| bookworm (security) | 6.1.112-1 | fixed |
| trixie | 6.10.11-1 | fixed |
| sid | 6.10.12-1 | fixed |
linux-4.19 (PTS) | jessie, jessie (lts) | 4.19.316-1~deb8u1 | fixed |
| stretch (security) | 4.19.232-1~deb9u1 | vulnerable |
| stretch (lts), stretch | 4.19.316-1~deb9u1 | fixed |
linux-5.10 (PTS) | stretch (lts), stretch | 5.10.218-1~deb9u1 | fixed |
xen (PTS) | jessie, jessie (lts) | 4.4.4lts5-0+deb8u1 | vulnerable |
| stretch (security), stretch (lts), stretch | 4.8.5.final+shim4.10.4-1+deb9u12 | vulnerable |
| buster (security), buster, buster (lts) | 4.11.4+107-gef32c7afa2-1 | vulnerable |
| bullseye | 4.14.6-1 | vulnerable |
| bullseye (security) | 4.14.5+94-ge49571868d-1 | vulnerable |
| bookworm | 4.17.3+10-g091466ba55-1~deb12u1 | fixed |
| sid, trixie | 4.17.3+36-g54dacb5c02-1 | fixed |
The information below is based on the following data on fixed versions.