CVE-2022-23034: Integer Underflow
A PV guest could DoS Xen while unmapping a grant To address XSA-380, reference counting was introduced for grant mappings for the case where a PV guest would have the IOMMU enabled. PV guests can request two forms of mappings. When both are in use for any individual mapping, unmapping of such a mapping can be requested in two steps. The reference count for such a mapping would then mistakenly be decremented twice. Underflow of the counters gets detected, resulting in the triggering of a hypervisor bug check.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2022-23034?
CVE-2022-23034 is classified as a high severity vulnerability that allows a PV guest to cause denial of service on Xen.
How do I fix CVE-2022-23034?
To remediate CVE-2022-23034, update Xen to a fixed version starting from 4.14.6-1 or later.
Who is affected by CVE-2022-23034?
CVE-2022-23034 affects users of Xen with IOMMU enabled configurations, particularly those running affected Xen versions.
What systems are impacted by CVE-2022-23034?
The vulnerability impacts systems using specific versions of Xen on Debian and Fedora, including Debian 9.0, Debian 11.0, and Fedora 34.
What actions should I take if my systems are vulnerable to CVE-2022-23034?
If your systems are vulnerable to CVE-2022-23034, apply the necessary updates to mitigate the risk.