CVE-2022-33746: Medium severity xen xapi vulnerability
P2M pool freeing may take excessively long The P2M pool backing second level address translation for guests may be of significant size. Therefore its freeing may take more time than is reasonable without intermediate preemption checks. Such checking for the need to preempt was so far missing.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2022-33746?
The severity of CVE-2022-33746 is medium with a severity value of 6.5.
Which software is affected by CVE-2022-33746?
CVE-2022-33746 affects Xen Xen, Fedoraproject Fedora versions 35, 36, and 37, as well as Debian Debian Linux version 11.0.
How long does the P2M pool freeing take in CVE-2022-33746?
The P2M pool freeing in CVE-2022-33746 may take more time than reasonable without intermediate preemption checks.
How can I fix CVE-2022-33746?
To fix CVE-2022-33746, update to the latest version of the affected software packages: Xen Xen (version 4.14.6-1 or higher), Fedoraproject Fedora (versions 35, 36, or 37), and Debian Debian Linux (version 11.0).
Where can I find more information about CVE-2022-33746?
You can find more information about CVE-2022-33746 in the following references: [Xen advisory](https://xenbits.xen.org/xsa/advisory-410.html), [Debian security tracker](https://security-tracker.debian.org/tracker/CVE-2022-33746), and [Openwall OSS Security mailing list](http://www.openwall.com/lists/oss-security/2022/10/11/3).