CVE-2022-26356: Medium severity xen xapi vulnerability
Racy interactions between dirty vram tracking and paging log dirty hypercalls Activation of log dirty mode done by XENDMOPtrackdirtyvram (was named HVMOPtrackdirtyvram before Xen 4.9) is racy with ongoing log dirty hypercalls. A suitably timed call to XENDMOPtrackdirtyvram can enable log dirty while another CPU is still in the process of tearing down the structures related to a previously enabled log dirty mode (XENDOMCTLSHADOWOPOFF). This is due to lack of mutually exclusive locking between both operations and can lead to entries being added in already freed slots, resulting in a memory leak.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-26356?
CVE-2022-26356 is a vulnerability caused by racy interactions between dirty vram tracking and paging log dirty hypercalls in Xen.
What is the severity of CVE-2022-26356?
The severity of CVE-2022-26356 is medium with a severity value of 5.6.
Which software is affected by CVE-2022-26356?
Xen versions between 4.0.0 and 4.12.0, Xen versions between 4.13.0 and 4.14.0, Xen versions between 4.15.0 and 4.16.0, Debian Linux 11.0, Fedora 34, and Fedora 35 are affected by CVE-2022-26356.
How can I fix CVE-2022-26356?
To fix CVE-2022-26356, update to Xen version 4.14.6-1, 4.14.5+94-ge49571868d-1, 4.17.1+2-gb773c48e36-1, or 4.17.2+55-g0b56bed864-1.
Where can I find more information about CVE-2022-26356?
More information about CVE-2022-26356 can be found at the following references: [1](http://www.openwall.com/lists/oss-security/2022/04/05/1), [2](http://xenbits.xen.org/xsa/advisory-397.html), [3](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6ETPM2OVZZ6KOS2L7QO7SIW6XWT5OW3F/).