DEBIAN-CVE-2022-26362
Advisory lineage Upstream: 1 Downstream: 1
Upstream
Downstream
Published: 09 Jun 2022, 17:15
Last modified:28 Apr 2026, 20:24
Vulnerability Summary
Overall Risk (default)
medium
26/100 CVSS Score
6.4 MEDIUM
3.1 (osv_debian)
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
09 Jun 2022, 17:15
Published
Vulnerability first disclosed
28 Apr 2026, 20:24
Last Modified
Vulnerability information updated
Description
x86 pv: Race condition in typeref acquisition Xen maintains a type reference count for pages, in addition to a regular reference count. This scheme is used to maintain invariants required for Xen's safety, e.g. PV guests may not have direct writeable access to pagetables; updates need auditing by Xen. Unfortunately, the logic for acquiring a type reference has a race condition, whereby a safely TLB flush is issued too early and creates a window where the guest can re-establish the read/write mapping before writeability is prohibited.
CVSS Metrics
- v3.1•MEDIUM•Score: 6.4CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Affected Systems
- debian•xen
< 4.14.5+24-g87d90d511c-1 | < 4.16.2-1 | < 4.16.2-1 | < 4.16.2-1