Skip to content

kernel CVE-2022-26365

Moderate
rpkelly published GHSA-mq2f-883v-534f Jul 29, 2022

Package

kernel-5.10 (bottlerocket)

Affected versions

< 1.9.0

Patched versions

1.9.0
kernel-5.15 (bottlerocket)
< 1.9.0
1.9.0
kernel-5.4 (bottlerocket)
< 1.9.0
1.9.0

Description

Block and network PV device frontends don’t zero memory regions before sharing them with the backend, and the granularity of the grant table doesn’t allow sharing less than a 4K page. This leads to unrelated data residing in the same 4K page as data shared with a backend being accessible by that backend.

Severity

Moderate

CVE ID

CVE-2022-26365

Weaknesses

No CWEs