SB2023010302 - Security restrictions bypass in Xen APIC accesses feature
Published: January 3, 2023
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper Privilege Management (CVE-ID: CVE-2022-42327)
The vulnerability allows a malicious guest to escalate privileges on the system.
The vulnerability exists due to improper privilege management. A malicious guest is able to access unintended shared memory page, read and write the global shared xAPIC page by moving the local APIC out of xAPIC mode.
Remediation
Install update from vendor's website.
References
- https://xenbits.xenproject.org/xsa/advisory-412.txt
- http://xenbits.xen.org/xsa/advisory-412.html
- http://www.openwall.com/lists/oss-security/2022/11/01/3
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZLI2NPNEH7CNJO3VZGQNOI4M4EWLNKPZ/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YTMITQBGC23MSDHUCAPCVGLMVXIBXQTQ/