Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

David Vrabel

#21397of 53,638
11.4Total CVSS
Vulnerabilities · 2
Medium
2
PT-2022-7325
6.5
2022-11-01
Xenstore · Xenstore · CVE-2022-42321
**Name of the Vulnerable Software and Affected Versions** Xenstore (affected versions not specified) **Description** The issue is related to uncontrolled recursion in Xenstore operations, such as deleting a sub-tree of Xenstore nodes. This can lead to stack exhaustion on xenstored, resulting in a crash. The problem arises when there are sufficiently deep nesting levels. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2015-3843
4.9
2015-01-12
Xen · Xen · CVE-2014-6268
**Name of the Vulnerable Software and Affected Versions** Xen versions 4.4.x **Description** The issue allows local guest users to cause a denial of service, resulting in a host crash. This can be achieved through vectors involving an uninitialized FIFO-based event channel control block, specifically when binding or moving an event to a different VCPU. **Recommendations** For Xen version 4.4.x, consider restricting access to the evtchn fifo set pending function as a temporary workaround until a patch is available.