CVE Vulnerabilities

CVE-2022-33746

Improper Resource Shutdown or Release

Published: Oct 11, 2022 | Modified: Feb 04, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

P2M pool freeing may take excessively long The P2M pool backing second level address translation for guests may be of significant size. Therefore its freeing may take more time than is reasonable without intermediate preemption checks. Such checking for the need to preempt was so far missing.

Weakness

The product does not release or incorrectly releases a resource before it is made available for re-use.

Affected Software

Name Vendor Start Version End Version
Xen Xen 4.13.0 (including) 4.16.1 (including)
Xen Ubuntu bionic *
Xen Ubuntu kinetic *
Xen Ubuntu lunar *
Xen Ubuntu mantic *
Xen Ubuntu trusty *
Xen Ubuntu xenial *

Potential Mitigations

  • Use a language that does not allow this weakness to occur or provides constructs that make this weakness easier to avoid.
  • For example, languages such as Java, Ruby, and Lisp perform automatic garbage collection that releases memory for objects that have been deallocated.

References