Bug 1197423 - (CVE-2022-26356) VUL-0: CVE-2022-26356: xen: Racy interactions between dirty vram tracking and paging log dirty hypercalls (XSA-397)
(CVE-2022-26356)
VUL-0: CVE-2022-26356: xen: Racy interactions between dirty vram tracking and...
Status: NEW
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P3 - Medium : Normal
: ---
Assigned To: Security Team bot
Security Team bot
https://smash.suse.de/issue/326998/
CVSSv3.1:SUSE:CVE-2022-26356:6.7:(AV:...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2022-03-23 09:25 UTC by Thomas Leroy
Modified: 2022-08-11 23:15 UTC (History)
4 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments
XSA-397 patches (2.49 KB, application/gzip)
2022-03-23 09:25 UTC, Thomas Leroy
Details

Note You need to log in before you can comment on or make changes to this bug.
Comment 3 Thomas Leroy 2022-03-25 09:16:30 UTC
Every codestream is affected:

- SUSE:SLE-11-SP1:Update:Teradata
- SUSE:SLE-11-SP3:Update	
- SUSE:SLE-11-SP3:Update:Teradata 	
- SUSE:SLE-11-SP4:Update 	
- SUSE:SLE-12-SP2:Update 	
- SUSE:SLE-12-SP3:Update
- SUSE:SLE-12-SP4:Update 	
- SUSE:SLE-12-SP5:Update	
- SUSE:SLE-15:Update 	
- SUSE:SLE-15-SP1:Update
- SUSE:SLE-15-SP2:Update
- SUSE:SLE-15-SP3:Update	
- SUSE:SLE-15-SP4:Update

Note that SUSE:SLE-11-SP1:Update:Teradata is EoL in the end of this month
Comment 5 Alexander Bergmann 2022-04-05 13:48:11 UTC
Public!

https://xenbits.xen.org/xsa/advisory-397.html

            Xen Security Advisory CVE-2022-26356 / XSA-397
                               version 2

 Racy interactions between dirty vram tracking and paging log dirty hypercalls

UPDATES IN VERSION 2
====================

Public release.

ISSUE DESCRIPTION
=================

Activation of log dirty mode done by XEN_DMOP_track_dirty_vram (was named
HVMOP_track_dirty_vram before Xen 4.9) is racy with ongoing log dirty
hypercalls.  A suitably timed call to XEN_DMOP_track_dirty_vram can enable
log dirty while another CPU is still in the process of tearing down the
structures related to a previously enabled log dirty mode
(XEN_DOMCTL_SHADOW_OP_OFF).  This is due to lack of mutually exclusive locking
between both operations and can lead to entries being added in already freed
slots, resulting in a memory leak.

IMPACT
======

An attacker can cause Xen to leak memory, eventually leading to a Denial of
Service (DoS) affecting the entire host.

VULNERABLE SYSTEMS
==================

All Xen versions from at least 4.0 onwards are vulnerable.

Only x86 systems are vulnerable.  Arm systems are not vulnerable.

Only domains controlling an x86 HVM guest using Hardware Assisted Paging (HAP)
can leverage the vulnerability.  On common deployments this is limited to
domains that run device models on behalf of guests.

MITIGATION
==========

Using only PV or PVH guests and/or running HVM guests in shadow mode will avoid
the vulnerability.

CREDITS
=======

This issue was discovered by Roger Pau Monné of Citrix.

RESOLUTION
==========

Applying the appropriate attached patch resolves this issue.

Note that patches for released versions are generally prepared to
apply to the stable branches, and may not apply cleanly to the most
recent release tarball.  Downstreams are encouraged to update to the
tip of the stable branch before applying these patches.

xsa397.patch           xen-unstable
xsa397-4.16.patch      Xen 4.16.x - Xen 4.15.x
xsa397-4.14.patch      Xen 4.14.x - Xen 4.13.x
xsa397-4.12.patch      Xen 4.12.x

$ sha256sum xsa397*
49c663e2bb9131dbc2488e12487f79bdf0dafd51a32413cbf3964e39d8779cae  xsa397.patch
24f95f47b79739c9cb5b9110137c802989356c82d0aa27963b5ac7e33f667285  xsa397-4.12.patch
9af14f90ba10d074425eb6072a6c648082c92c1cf8b6f881f57ed2fc13d6e49d  xsa397-4.14.patch
ff5dd3b7a8dbf349c3b832b7916322c0296fa59c7f9cd2ba30858989add5f65c  xsa397-4.16.patch
$

DEPLOYMENT DURING EMBARGO
=========================

Deployment of the patches described above (or others which are substantially
similar) is permitted during the embargo, even on public-facing systems with
untrusted guest users and administrators.

But: Distribution of updated software (except to other members of the
predisclosure list) or deployment of mitigations is prohibited.

Predisclosure list members who wish to deploy significantly different
patches and/or mitigations, please contact the Xen Project Security
Team.


(Note: this during-embargo deployment notice is retained in
post-embargo publicly released Xen Project advisories, even though it
is then no longer applicable.  This is to enable the community to have
oversight of the Xen Project Security Team's decisionmaking.)

For more information about permissible uses of embargoed information,
consult the Xen Project community's agreed Security Policy:
  http://www.xenproject.org/security-policy.html
Comment 6 OBSbugzilla Bot 2022-04-05 17:50:03 UTC
This is an autogenerated message for OBS integration:
This bug (1197423) was mentioned in
https://build.opensuse.org/request/show/967124 Factory / xen
Comment 11 Charles Arnold 2022-04-13 12:57:08 UTC
Backports and submissions to SLE12-SP2 complete.
No further work planned.
Comment 12 Swamp Workflow Management 2022-04-20 19:20:21 UTC
SUSE-SU-2022:1285-1: An update that fixes 9 vulnerabilities is now available.

Category: security (important)
Bug References: 1196915,1197423,1197425,1197426
CVE References: CVE-2021-26401,CVE-2022-0001,CVE-2022-0002,CVE-2022-26356,CVE-2022-26357,CVE-2022-26358,CVE-2022-26359,CVE-2022-26360,CVE-2022-26361
JIRA References: 
Sources used:
SUSE OpenStack Cloud Crowbar 9 (src):    xen-4.11.4_28-2.73.1
SUSE OpenStack Cloud 9 (src):    xen-4.11.4_28-2.73.1
SUSE Linux Enterprise Server for SAP 12-SP4 (src):    xen-4.11.4_28-2.73.1
SUSE Linux Enterprise Server 12-SP4-LTSS (src):    xen-4.11.4_28-2.73.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 13 Swamp Workflow Management 2022-04-22 10:20:01 UTC
SUSE-SU-2022:1300-1: An update that fixes 9 vulnerabilities is now available.

Category: security (important)
Bug References: 1194267,1196915,1197423,1197425,1197426
CVE References: CVE-2021-26401,CVE-2022-0001,CVE-2022-0002,CVE-2022-26356,CVE-2022-26357,CVE-2022-26358,CVE-2022-26359,CVE-2022-26360,CVE-2022-26361
JIRA References: 
Sources used:
SUSE Manager Server 4.1 (src):    xen-4.13.4_08-150200.3.50.1
SUSE Manager Retail Branch Server 4.1 (src):    xen-4.13.4_08-150200.3.50.1
SUSE Manager Proxy 4.1 (src):    xen-4.13.4_08-150200.3.50.1
SUSE Linux Enterprise Server for SAP 15-SP2 (src):    xen-4.13.4_08-150200.3.50.1
SUSE Linux Enterprise Server 15-SP2-LTSS (src):    xen-4.13.4_08-150200.3.50.1
SUSE Linux Enterprise Server 15-SP2-BCL (src):    xen-4.13.4_08-150200.3.50.1
SUSE Linux Enterprise Realtime Extension 15-SP2 (src):    xen-4.13.4_08-150200.3.50.1
SUSE Linux Enterprise Micro 5.0 (src):    xen-4.13.4_08-150200.3.50.1
SUSE Linux Enterprise High Performance Computing 15-SP2-LTSS (src):    xen-4.13.4_08-150200.3.50.1
SUSE Linux Enterprise High Performance Computing 15-SP2-ESPOS (src):    xen-4.13.4_08-150200.3.50.1
SUSE Enterprise Storage 7 (src):    xen-4.13.4_08-150200.3.50.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 14 Swamp Workflow Management 2022-04-25 16:22:27 UTC
SUSE-SU-2022:1359-1: An update that fixes 9 vulnerabilities is now available.

Category: security (important)
Bug References: 1196915,1197423,1197425,1197426
CVE References: CVE-2021-26401,CVE-2022-0001,CVE-2022-0002,CVE-2022-26356,CVE-2022-26357,CVE-2022-26358,CVE-2022-26359,CVE-2022-26360,CVE-2022-26361
JIRA References: 
Sources used:
SUSE Linux Enterprise Server for SAP 15 (src):    xen-4.10.4_34-150000.3.74.1
SUSE Linux Enterprise High Performance Computing 15-LTSS (src):    xen-4.10.4_34-150000.3.74.1
SUSE Linux Enterprise High Performance Computing 15-ESPOS (src):    xen-4.10.4_34-150000.3.74.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 15 Swamp Workflow Management 2022-04-25 19:33:05 UTC
SUSE-SU-2022:1375-1: An update that fixes 10 vulnerabilities is now available.

Category: security (important)
Bug References: 1182846,1196915,1197423,1197425,1197426
CVE References: CVE-2021-20257,CVE-2021-26401,CVE-2022-0001,CVE-2022-0002,CVE-2022-26356,CVE-2022-26357,CVE-2022-26358,CVE-2022-26359,CVE-2022-26360,CVE-2022-26361
JIRA References: 
Sources used:
SUSE Linux Enterprise Server 12-SP2-BCL (src):    xen-4.7.6_22-43.88.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 16 Swamp Workflow Management 2022-04-26 13:18:56 UTC
SUSE-SU-2022:1408-1: An update that fixes 9 vulnerabilities is now available.

Category: security (important)
Bug References: 1196915,1197423,1197425,1197426
CVE References: CVE-2021-26401,CVE-2022-0001,CVE-2022-0002,CVE-2022-26356,CVE-2022-26357,CVE-2022-26358,CVE-2022-26359,CVE-2022-26360,CVE-2022-26361
JIRA References: 
Sources used:
SUSE OpenStack Cloud Crowbar 8 (src):    xen-4.9.4_28-3.103.1
SUSE OpenStack Cloud 8 (src):    xen-4.9.4_28-3.103.1
SUSE Linux Enterprise Server for SAP 12-SP3 (src):    xen-4.9.4_28-3.103.1
SUSE Linux Enterprise Server 12-SP3-LTSS (src):    xen-4.9.4_28-3.103.1
SUSE Linux Enterprise Server 12-SP3-BCL (src):    xen-4.9.4_28-3.103.1
HPE Helion Openstack 8 (src):    xen-4.9.4_28-3.103.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 17 Swamp Workflow Management 2022-05-03 19:18:23 UTC
SUSE-SU-2022:1505-1: An update that fixes 6 vulnerabilities is now available.

Category: security (moderate)
Bug References: 1197423,1197425,1197426
CVE References: CVE-2022-26356,CVE-2022-26357,CVE-2022-26358,CVE-2022-26359,CVE-2022-26360,CVE-2022-26361
JIRA References: 
Sources used:
SUSE Linux Enterprise Software Development Kit 12-SP5 (src):    xen-4.12.4_22-3.66.1
SUSE Linux Enterprise Server 12-SP5 (src):    xen-4.12.4_22-3.66.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 18 Swamp Workflow Management 2022-05-03 19:19:56 UTC
SUSE-SU-2022:1506-1: An update that fixes 6 vulnerabilities is now available.

Category: security (moderate)
Bug References: 1197423,1197425,1197426
CVE References: CVE-2022-26356,CVE-2022-26357,CVE-2022-26358,CVE-2022-26359,CVE-2022-26360,CVE-2022-26361
JIRA References: 
Sources used:
openSUSE Leap 15.3 (src):    xen-4.14.4_04-150300.3.24.1
SUSE Linux Enterprise Module for Server Applications 15-SP3 (src):    xen-4.14.4_04-150300.3.24.1
SUSE Linux Enterprise Module for Basesystem 15-SP3 (src):    xen-4.14.4_04-150300.3.24.1
SUSE Linux Enterprise Micro 5.2 (src):    xen-4.14.4_04-150300.3.24.1
SUSE Linux Enterprise Micro 5.1 (src):    xen-4.14.4_04-150300.3.24.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 21 Swamp Workflow Management 2022-06-23 13:18:37 UTC
SUSE-SU-2022:2158-1: An update that fixes 9 vulnerabilities is now available.

Category: security (important)
Bug References: 1197423,1197425,1197426,1199965,1199966
CVE References: CVE-2022-26356,CVE-2022-26357,CVE-2022-26358,CVE-2022-26359,CVE-2022-26360,CVE-2022-26361,CVE-2022-26362,CVE-2022-26363,CVE-2022-26364
JIRA References: 
Sources used:
SUSE Linux Enterprise Server for SAP 15-SP1 (src):    xen-4.12.4_24-150100.3.72.1
SUSE Linux Enterprise Server 15-SP1-LTSS (src):    xen-4.12.4_24-150100.3.72.1
SUSE Linux Enterprise Server 15-SP1-BCL (src):    xen-4.12.4_24-150100.3.72.1
SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS (src):    xen-4.12.4_24-150100.3.72.1
SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS (src):    xen-4.12.4_24-150100.3.72.1
SUSE Enterprise Storage 6 (src):    xen-4.12.4_24-150100.3.72.1
SUSE CaaS Platform 4.0 (src):    xen-4.12.4_24-150100.3.72.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.