Description
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Published: 2024-05-03
Score: 5.5 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 19 Dec 2024 11:45:00 +0000


Thu, 19 Dec 2024 11:15:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: vfio/type1: Unpin zero pages There's currently a reference count leak on the zero page. We increment the reference via pin_user_pages_remote(), but the page is later handled as an invalid/reserved page, therefore it's not accounted against the user and not unpinned by our put_pfn(). Introducing special zero page handling in put_pfn() would resolve the leak, but without accounting of the zero page, a single user could still create enough mappings to generate a reference count overflow. The zero page is always resident, so for our purposes there's no reason to keep it pinned. Therefore, add a loop to walk pages returned from pin_user_pages_remote() and unpin any zero pages. This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Title vfio/type1: Unpin zero pages kernel: vfio/type1: Unpin zero pages
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

No data.

cve-icon MITRE

Status: REJECTED

Assigner: Linux

Published:

Updated: 2024-12-19T11:01:44.556Z

Reserved: 2024-05-03T14:55:07.145Z

Link: CVE-2022-48700

cve-icon Vulnrichment

Updated:

cve-icon NVD

Status : Rejected

Published: 2024-05-03T16:15:08.500

Modified: 2024-12-19T11:15:30.050

Link: CVE-2022-48700

cve-icon Redhat

Severity : Low

Publid Date: 2024-05-03T00:00:00Z

Links: CVE-2022-48700 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses

No weakness.