CVE-2022-42310
published 2022-11-01CVE-2022-42310: Xenstore: Guests can create orphaned Xenstore nodes By creating multiple nodes inside a transaction resulting in an error, a malicious guest can create…
PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.26%
18.0th percentile
Xenstore: Guests can create orphaned Xenstore nodes By creating multiple nodes inside a transaction resulting in an error, a malicious guest can create orphaned nodes in the Xenstore data base, as the cleanup after the error will not remove all nodes already created. When the transaction is committed after this situation, nodes without a valid parent can be made permanent in the data base.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | xen | < xen 4.16.2+90-g0d39a6d1ae-1 (bookworm) | xen 4.16.2+90-g0d39a6d1ae-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| xen | xen | >= 0 < 4.14.5+86-g1c354767d5-1 | 4.14.5+86-g1c354767d5-1 |
| xen | xen | >= 0 < 4.16.2+90-g0d39a6d1ae-1 | 4.16.2+90-g0d39a6d1ae-1 |
| xen | xen | >= 0 < 4.16.2+90-g0d39a6d1ae-1 | 4.16.2+90-g0d39a6d1ae-1 |
| xen | xen | >= 0 < 4.16.2+90-g0d39a6d1ae-1 | 4.16.2+90-g0d39a6d1ae-1 |
| xen | xen | >= 4.9.0 < 4.13.0 | 4.13.0 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gw3c-jrpr-59hg: Xenstore: Guests can create orphaned Xenstore nodes By creating multiple nodes inside a transaction resulting in an error, a malicious guest can creat
ghsa_unreviewed·2022-11-01
CVE-2022-42310 [MEDIUM] CWE-459 GHSA-gw3c-jrpr-59hg: Xenstore: Guests can create orphaned Xenstore nodes By creating multiple nodes inside a transaction resulting in an error, a malicious guest can creat
Xenstore: Guests can create orphaned Xenstore nodes By creating multiple nodes inside a transaction resulting in an error, a malicious guest can create orphaned nodes in the Xenstore data base, as the cleanup after the error will not remove all nodes already created. When the transaction is committed after this situation, nodes without a valid parent can be made permanent in the data base.
OSV
CVE-2022-42310: Xenstore: Guests can create orphaned Xenstore nodes By creating multiple nodes inside a transaction resulting in an error, a malicious guest can creat
osv·2022-11-01·CVSS 5.5
CVE-2022-42310 [MEDIUM] CVE-2022-42310: Xenstore: Guests can create orphaned Xenstore nodes By creating multiple nodes inside a transaction resulting in an error, a malicious guest can creat
Xenstore: Guests can create orphaned Xenstore nodes By creating multiple nodes inside a transaction resulting in an error, a malicious guest can create orphaned nodes in the Xenstore data base, as the cleanup after the error will not remove all nodes already created. When the transaction is committed after this situation, nodes without a valid parent can be made permanent in the data base.
Debian
CVE-2022-42310: xen - Xenstore: Guests can create orphaned Xenstore nodes By creating multiple nodes i...
vendor_debian·2022·CVSS 5.5
CVE-2022-42310 [MEDIUM] CVE-2022-42310: xen - Xenstore: Guests can create orphaned Xenstore nodes By creating multiple nodes i...
Xenstore: Guests can create orphaned Xenstore nodes By creating multiple nodes inside a transaction resulting in an error, a malicious guest can create orphaned nodes in the Xenstore data base, as the cleanup after the error will not remove all nodes already created. When the transaction is committed after this situation, nodes without a valid parent can be made permanent in the data base.
Scope: local
bookworm: resolved (fixed in 4.16.2+90-g0d39a6d1ae-1)
bullseye: resolved (fixed in 4.14.5+86-g1c354767d5-1)
forky: resolved (fixed in 4.16.2+90-g0d39a6d1ae-1)
sid: resolved (fixed in 4.16.2+90-g0d39a6d1ae-1)
trixie: resolved (fixed in 4.16.2+90-g0d39a6d1ae-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.openwall.com/lists/oss-security/2022/11/01/5http://xenbits.xen.org/xsa/advisory-415.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YTMITQBGC23MSDHUCAPCVGLMVXIBXQTQ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YZVXG7OOOXCX6VIPEMLFDPIPUTFAYWPE/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZLI2NPNEH7CNJO3VZGQNOI4M4EWLNKPZ/https://security.gentoo.org/glsa/202402-07https://www.debian.org/security/2022/dsa-5272https://xenbits.xenproject.org/xsa/advisory-415.txthttp://www.openwall.com/lists/oss-security/2022/11/01/5http://xenbits.xen.org/xsa/advisory-415.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YTMITQBGC23MSDHUCAPCVGLMVXIBXQTQ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YZVXG7OOOXCX6VIPEMLFDPIPUTFAYWPE/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZLI2NPNEH7CNJO3VZGQNOI4M4EWLNKPZ/https://security.gentoo.org/glsa/202402-07https://www.debian.org/security/2022/dsa-5272https://xenbits.xenproject.org/xsa/advisory-415.txt
2022-11-01
Published