[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

256148

 
 

909

 
 

199106

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2022-33748Date: (C)2022-10-12   (M)2024-02-12


lock order inversion in transitive grant copy handling As part of XSA-226 a missing cleanup call was inserted on an error handling path. While doing so, locking requirements were not paid attention to. As a result two cooperating guests granting each other transitive grants can cause locks to be acquired nested within one another, but in respectively opposite order. With suitable timing between the involved grant copy operations this may result in the locking up of a CPU.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : 5.6CVSS Score :
Exploit Score: 1.1Exploit Score:
Impact Score: 4.0Impact Score:
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: LOCALAccess Vector:
Attack Complexity: HIGHAccess Complexity:
Privileges Required: LOWAuthentication:
User Interaction: NONEConfidentiality:
Scope: CHANGEDIntegrity:
Confidentiality: NONEAvailability:
Integrity: NONE 
Availability: HIGH 
  
Reference:
DSA-5272
FEDORA-2022-5b594b82ac
FEDORA-2022-99af00f60e
FEDORA-2022-d80cc73088
GLSA-202402-07
http://www.openwall.com/lists/oss-security/2022/10/11/2
http://xenbits.xen.org/xsa/advisory-411.html
https://xenbits.xenproject.org/xsa/advisory-411.txt

CWE    1
CWE-755
OVAL    15
oval:org.secpod.oval:def:610240
oval:org.secpod.oval:def:3300719
oval:org.secpod.oval:def:89047969
oval:org.secpod.oval:def:89047889
...

© SecPod Technologies