Use-after-free Vulnerability in Xen's x86 Shadow and Log-Dirty Mode
CVE-2022-42332
What is CVE-2022-42332?
In certain environments where Hardware Assisted Paging (HAP) is not available, the Xen Hypervisor operates in shadow mode, which relies on a memory pool for shadow page tables and auxiliary structures. During migration or snapshot processes, it also utilizes log-dirty mode for memory allocation tracking. However, the Xen architecture fails to properly account for memory demands of the log-dirty infrastructure when establishing new shadow page tables. Consequently, these tables may be prematurely freed while still being accessed by other operations, leading to potential memory corruption and instability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
xen consult Xen advisory XSA-427
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved