PT-2022-7321 · Xenstore+1 · Xenstore+1

Julien Grall

·

Published

2022-11-01

·

Updated

2022-12-12

·

CVE-2022-42313

CVSS v3.1

6.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Xenstore (affected versions not specified)
Description The issue is related to the uncontrolled allocation of resources in Xenstore, which can lead to a Denial of Service (DoS) of xenstored. Malicious guests can cause xenstored to allocate large amounts of memory through various methods, including issuing new requests without reading responses, generating a large number of watch events, creating multiple nodes with maximum size and path length, and accessing many nodes inside a transaction.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

BDU:2024-03577
CVE-2022-42313
DSA-5272-1
OPENSUSE-SU-2022_3947-1
OPENSUSE-SU-2022_4007-1
SUSE-SU-2022:3925-1
SUSE-SU-2022:3928-1
SUSE-SU-2022:3947-1
SUSE-SU-2022:3960-1
SUSE-SU-2022:3971-1
SUSE-SU-2022:4007-1
SUSE-SU-2022:4051-1
SUSE-SU-2022:4241-1
SUSE-SU-2022:4332-1

Affected Products

Suse
Xenstore