SB2022021736 - SUSE update for xen
Published: February 17, 2022
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 3 secuirty vulnerabilities.
1) Incorrect authorization (CVE-ID: CVE-2022-23033)
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to guest_physmap_remove_page() function does not remove p2m mappings. A local user issuing a set/way cache maintenance instruction, then calling the XENMEM_decrease_reservation hypercall to give back memory pages to Xen, can cause information leaks, Denial of Service (DoS), or escalate privileges on the system.
2) Integer underflow (CVE-ID: CVE-2022-23034)
The vulnerability allows a local user can perform a denial of service attack.
The vulnerability exists due to integer underflow when unmapping a grant to address XSA-380. A local user can request two forms of mappings to perform a denial of service attack.
3) Incomplete cleanup (CVE-ID: CVE-2022-23035)
The vulnerability allows a local attacker to escalate privileges on the system.
The vulnerability exists due to insufficient cleanup of passed-through device IRQs. An attacker with physical access can cause a Denial of Service (DoS) and escalate privileges on the system.
Remediation
Install update from vendor's website.