cbcvebase.
CVE-2022-42317
published 2022-11-01

CVE-2022-42317: Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities…

PriorityP423medium6.5CVSS 3.1
AVLACLPRLUINSCCNINAH
EPSS
0.24%
15.7th percentile
Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Malicious guests can cause xenstored to allocate vast amounts of memory, eventually resulting in a Denial of Service (DoS) of xenstored. There are multiple ways how guests can cause large memory allocations in xenstored: - - by issuing new requests to xenstored without reading the responses, causing the responses to be buffered in memory - - by causing large number of watch events to be generated via setting up multiple xenstore watches and then e.g. deleting many xenstore nodes below the watched path - - by creating as many nodes as allowed with the maximum allowed size and path length in as many transactions as possible - - by accessing many nodes inside a transaction

Affected

9 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianxen< xen 4.16.2+90-g0d39a6d1ae-1 (bookworm)xen 4.16.2+90-g0d39a6d1ae-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
xenxen>= 0 < 4.14.5+86-g1c354767d5-14.14.5+86-g1c354767d5-1
xenxen>= 0 < 4.16.2+90-g0d39a6d1ae-14.16.2+90-g0d39a6d1ae-1
xenxen>= 0 < 4.16.2+90-g0d39a6d1ae-14.16.2+90-g0d39a6d1ae-1
xenxen>= 0 < 4.16.2+90-g0d39a6d1ae-14.16.2+90-g0d39a6d1ae-1

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
osv6.5MEDIUM
vendor_debian6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.