Alpine: multiple xen packages: security update to 4.17.1-r1

low Tenable Cloud Security Plugin ID 424730

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Mishandling of guest SSBD selection on AMD hardware The current logic to set SSBD on AMD Family 17h and
Hygon Family 18h processors requires that the setting of SSBD is coordinated at a core level, as the
setting is shared between threads. Logic was introduced to keep track of how many threads require SSBD
active in order to coordinate it, such logic relies on using a per-core counter of threads that have SSBD
active. When running on the mentioned hardware, it's possible for a guest to under or overflow the thread
counter, because each write to VIRT_SPEC_CTRL.SSBD by the guest gets propagated to the helper that does
the per-core active accounting. Underflowing the counter causes the value to get saturated, and thus
attempts for guests running on the same core to set SSBD won't have effect because the hypervisor assumes
it's already active. (CVE-2022-42336)

See Also

https://security.alpinelinux.org/vuln/CVE-2022-42336

Plugin Details

Severity: Low

ID: 424730

Version: Revision 1.10

Type: Local

Published: 4/4/2025

Updated: 7/2/2026

Supported Sensors: Agentless Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 1.2

Percentile: 0.01

CVSS v2

Risk Factor: Low

Base Score: 1.7

Temporal Score: 1.3

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:P/A:N

CVSS Score Source: CVE-2022-42336

CVSS v3

Risk Factor: Low

Base Score: 3.3

Temporal Score: 2.9

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 5/16/2023

Reference Information

CVE: CVE-2022-42336