CVE-2022-33747: Debian Linux
Low severity, CVSS 3.8. EPSS: 0.3% chance of exploitation in the next 30 days.
Arm: unbounded memory consumption for 2nd-level page tables Certain actions require e.g. removing pages from a guest's P2M (Physical-to-Machine) mapping. When large pages are in use to map guest pages in the 2nd-stage page tables, such a removal operation may incur a memory allocation (to replace a large mapping with individual smaller ones). These memory allocations are taken from the global memory pool. A malicious guest might be able to cause the global memory pool to be exhausted by manipulating its own P2M mappings.
Affected products
- Debian Debian Linux: version 11.0 only
- Fedoraproject Fedora: version 35 only; version 36 only; version 37 only
- Xen Xen: any version
Published 2022-10-11. Last modified 2026-06-17.